Invoke-PSImage takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image. It generates a one liner for executing either from a file of from the web. Example of usage is embedding the PowerShell code from the Invoke-Mimikatz module and embed it into an image file. By calling the image file from a macro for example, the macro will download the picture and execute the PowerShell code, which in this case will dump the passwords.
| Technique | Procedure example |
|---|---|
| T1027.003 Steganography |
Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file. |
| T1027.009 Embedded Payloads |
Invoke-PSImage can be used to embed payload data within a new image file. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.