Invoke-PSImage

MITRE
Tipo Malware:
Tool
Prima attivita:
Unknown
Ultima attivita:
Unknown
Dettagli:

[Invoke-PSImage](https://attack.mitre.org/software/S0231) takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image. It generates a one liner for executing either from a file of from the web. Example of usage is embedding the PowerShell code from the Invoke-Mimikatz module and embed it into an image file. By calling the image file from a macro for example, the macro will download the picture and execute the PowerShell code, which in this case will dump the passwords. (Citation: GitHub Invoke-PSImage)

Tecniche Associate (2)
ID ATT&CK Tattiche
T1027.003 Steganography -
T1027.009 Embedded Payloads -
Usato da Attori (1)
Metadata
ID: 759
Created: 13/01/2026 17:48
Updated: 10/05/2026 16:00