
Microsoft Windows Is Being Hacked If You See These JPEG Images
Windows Users Warned As Microsoft Paint And JPEG Images Used In Latest Hack Attacks
When you think of sophisticated hack attacks, the chances are that the much-derided MS Paint application and the use of basic JPEG images do not immediately spring to mind. Yet here we are, with a critical warning being issued as an advanced threat group colloquially known as Reaper, but more formally identified as APT37, using just these tools to deploy a truly dangerous remote access trojan called RoKRAT. You might be more used to reading about images stolen by hackers than deployed by them as an integral part of an attack, but the risk is very real indeed as security researchers at the Genians Security Center have warned.
The latest RoKRAT attack report has revealed how the APT37 hackers are using steganography to obfuscate malware code, which is then injected into the MS Paint process during the Microsoft Windows cyberattacks. Why do this? Because it makes detection, and therefore prevention, much harder.
APT37 'employs a two-stage encrypted shellcode injection method to hinder analysis,' the researchers warned, with downloaded images as part of the attack. The report said the malware analysts observed that 'the RoKRAT module is embedded within the JPEG image format.'
The RoKRAT attack module itself was concealed, the researchers said, in images named Father.jpg, downloaded from a Dropbox drive. There were two photos of a man, a harmless version of which can be viewed within the report itself, but 'the underlying malware structure remained the same.'
What Is Steganography?
Steganography, from the Greek steganographia, combining words meaning concealed and writing, is just that: the 'art' of concealing information within a different medium so that it is not immediately evident to even a skilled observer. In the world of cybersecurity, steganography is most commonly seen, or not, of course, as malicious code hiding within a seemingly harmless image. This is not a new technique by any means. I feel a confession coming on. Some 25 years ago, someone looking very much like me employed just such a technique to capture keyboard output and hide it in an image file for later extraction. Hackers have known about and deployed steganography forever. Which does not make it an outdated technique or any the easier to detect when looking for malicious code. And that, dear reader, is why the APT37 attackers are deploying it in these latest RaKRAT campaigns.
'When shellcode is injected into the mspaint.exe process to perform a fileless attack,' the researchers warned, 'detection by signature- or pattern-based security solutions may be difficult.' But a mature Endpoint Detection and Response solution can identify 'external communications initiated via shellcode and the Dropbox API,' which would quickly halt the Microsoft Windows attack.
For mere mortals without access to such enterprise tools, there's another mitigation method: beware of the phishing tactics used initially to distribute the malware. These consist of compressed archives containing Windows shortcut links. You can read about mitigating Microsoft LNK cyberattacks here. I have reached out to Microsoft for a statement rearing the latest APT37 campaign. In the meantime, a spokesperson previously advised that: 'Windows identifies LNK shortcut files as a potentially dangerous file type, which means that when a user attempts to open one that had been downloaded from the internet, a security warning is automatically triggered. This warning, quite correctly, advises the user not to open files from unknown sources. We strongly recommend heeding this warning.'

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles
Yahoo
6 minutes ago
- Yahoo
Exclusive-HSBC plans major global expansion of office, staff surveillance, documents show
By Stefania Spezzati and Iain Withers LONDON (Reuters) -HSBC plans to step up surveillance of staff and buildings by adding more cameras and biometric access to its premises globally, internal documents seen by Reuters show, a move that comes amid growing concerns about companies' extensive monitoring of workers. As part of its "global security strategy", the bank plans a four-fold increase in the number of cameras at its new building in the City of London, a site about half the size of its existing office in Canary Wharf, an internal presentation by the bank's protective security team dated May 2025, seen by Reuters, shows. According to the presentation, the new London building is expected to have an estimated 1,754 cameras, up from about 444 devices installed in its current global headquarters in Canary Wharf in London. It also plans to double its biometric readers to access the new building to 779 from 350. Under the plan, reported here for the first time, access to HSBC's top-tier buildings, including in Britain and the U.S., should be based on biometric verification, including full-hand recognition. Access can also be "digital", with employees expected to use their own mobile phones to badge in, the presentation document shows. HSBC, Europe's biggest bank by assets, employs more than 210,000 people globally, including more than 31,000 across the UK. Most employees are expected to use personal mobile phones with a firm-installed software on them to gain access. This has met with some resistance from staff, a person with knowledge of the policies said. As of the end of last year, most of the UK staff had yet to adhere to the biometric and digital access policy which the bank started to implement in 2022, in part because of opposition, according to the person. "The safety and security of our people is at the forefront of everything HSBC does," an HSBC representative told Reuters. "We regularly risk assess every building and dependant on the identified risk and vulnerabilities, we continue to invest in the latest cutting-edge technology to safeguard our colleagues, customers and visitors in line with industry standards," the bank added. Companies have increased surveillance of staff amid a shift to hybrid working, while advances in technology allow for more sophisticated controls. Banks in particular have stepped up monitoring to ensure the parts of their businesses that are heavily regulated comply with conduct rules. National privacy laws determine what companies can monitor. The extensive surveillance enabled by new technologies is raising concerns about risks to workers' rights and wellbeing, according to a May report by the Institute for Public Policy Research, a London-based think tank. In July, HSBC requested that senior staff globally report to the office at least four days a week, starting from October, a bank spokesperson said. Previously, the bank had no global policy on the matter, with approaches varying depending on the country, they said. As demands for office space grow again, the bank has decided to add to its planned City of London HQ, with a new smaller presence in Canary Wharf, Reuters reported. The documents seen by Reuters do not include references to the new Canary Wharf office space. The bank's security project is overseen by Diane Marchena, global head of protective security, who reports to Chief Operating Officer Suzy White, the person with knowledge of the matter said. Marchena and White declined to comment for this article. ISRAELI SURVEILLANCE TOOLS HSBC has been working with Israeli firm Octopus since at least 2024, adopting some of its tools for surveillance in the UK and Hong Kong and is planning more rollouts for monitoring, other documents outlining HSBC's global strategy seen by Reuters show. HSBC plans the deployment of Octopus tools in other countries such as India and Mexico this year, the documents, which are undated, show. Israel is one of the world's leading exporters of surveillance. Octopus says it sells its tools to buyers in 28 countries. Its technology has been reportedly used by entities, including the Israeli government to monitor some Israeli cities and a European Union-funded refugee camp on the Greek island of Samos. A representative for Octopus did not take Reuters calls seeking comment and the company did not respond to a Reuters email seeking comment. An HSBC spokesperson said the bank does not comment on vendors or suppliers. TRADING FLOORS In HSBC's new London building, the increased video surveillance will include cameras at entry and exit points of trading floors, the May 2025 presentation shows, and the use of artificial intelligence analytics. HSBC's budget for the initial rollout of the new London building surveillance was recently tripled to about $15 million, the person familiar with the matter said. According to the presentation, "theft incidents" in its Canary Wharf building "point to the need for increased CCTV capabilities on working floors," and that recent "crime data" showed an increase of incidents, including burglary, within a one-mile radius of the new office. The person familiar with the matter said that theft events on HSBC premises were mostly minor. Sign in to access your portfolio
Yahoo
6 minutes ago
- Yahoo
4 Ways You Can Leverage Microsoft To Make Money
Did you know you can leverage Microsoft to make money? Microsoft is a powerhouse in the software industry, but the company also has numerous branches that provide monetization opportunities for you. Trending Now: For You: Here are four ways you can use Microsoft to make money. Become a Microsoft Partner If you join the Microsoft AI Cloud Partner Program and gain access to resources and support tools to build solutions on its platforms, you could easily leverage this into some passive income streams. Not only can you access various benefits — including technical advisory hours, marketing resources and potentially cash incentives for building applications on Azure AI or Analytics services — but you can also segue this into an IT consulting business. With all this Microsoft tech at your disposal, you could develop a business plan, create your brand and market your services to attract clients without breaking a sweat. Consider offering services like network management, cybersecurity solutions or cloud services implementation as part of your IT consulting and money-making strategy. Speaking of partnerships, you could also consider working as an affiliate marketing partner with Microsoft. This would work by creating a blog or website and then incorporating affiliate links to Microsoft products or services. This would allow you to earn commissions when readers click on these links and make purchases. Find Out: Monetize Content With PubCenter If you create content, you can leverage Microsoft and use its pubCenter to monetize your content. With pubCenter, Microsoft advertisers compete for ad space on your website. When those ads populate on your website, you can make money. Let's say you have a blog in the travel industry. If an advertiser is trying to reach people who like to travel to promote a new suitcase, they might pay to place an ad on your blog. Unlike other advertising platforms that can take weeks to set up and don't tailor the content to your website, Microsoft pubCenter pushes ads that match your audience. If you're already doing the work of making and posting content, why not earn more money and gain value with pubCenter? Use Microsoft Rewards You don't have to be a content creator to make money with Microsoft — Microsoft Rewards can help you earn some extra cash with tasks you might already be doing. For example, you can earn points by simply performing everyday activities like searching the web with Bing or playing games on Xbox. Points work based on a level system. In Level 1, you can earn up to 30 points per day for searching Bing on a PC. Once you hit Level 2, you can start earning up to 90 points per day for Bing searches on your computer. These points can be accumulated and converted into different rewards, such as redeeming them for gift cards, nonprofit donations and sweepstakes entries. If you're an avid Google searcher, maybe it's time to switch to Bing to make extra money. Freelance for Microsoft If you have an entrepreneurial mindset, freelancing with Microsoft is another great option for making money. is a job task platform that can connect employers looking for freelancers for work done in Microsoft Word, Excel and PowerPoint. Developing strong Microsoft Office skills, especially in Excel, can open doors to roles like data entry, automation, and dashboard setup for various businesses that are often high-income earners. Freelancing using your Microsoft skills can help you earn extra money. Common jobs include typing PDF documents into Microsoft Word, creating tables and other content, and managing data and documents. You can not only work from the comfort of your home but also earn extra cash and refine your skill set. Most employers look for some type of proficiency in Microsoft, making freelancing a great opportunity to position yourself as a strong candidate. Caitlyn Moorhead contributed to the reporting for this article. More From GOBankingRates 5 Ways Trump Signing the GENIUS Act Could Impact Retirees9 Downsizing Tips for the Middle Class To Save on Monthly Expenses This article originally appeared on 4 Ways You Can Leverage Microsoft To Make Money
Yahoo
33 minutes ago
- Yahoo
Salesforce Pushes Data Cloud Adoption: Will It Anchor Growth?
Salesforce, Inc. CRM is making its Data Cloud platform a key part of its growth strategy. Data Cloud platform brings together customer data from multiple sources and makes it usable across Salesforce products. In the last reported financial results for the first quarter of fiscal 2026, the platform's annual recurring revenues soared 120% year over year and stored more than 22 trillion data points. Salesforce is witnessing a strong adoption trend for its Data Cloud platform. In the first quarter, nearly 60% of the company's top 100 deals included both Data Cloud and artificial intelligence (AI) capabilities, reflecting how valuable they can be if paired together. Additionally, roughly half of the new Data Cloud bookings in the last reported quarter came from existing clients, suggesting strong satisfaction and room for further growth. Salesforce is also integrating the Data Cloud platform with its other tools like Agentforce, Tableau and Slack. These connections make it easier for enterprises to activate their data and apply AI across operations. This integration could drive higher contract values and deeper customer relationships for Salesforce. To stay ahead in the competition across the enterprise software space, Salesforce will need to continuously upgrade its products and ensure quick, cost-effective deployment for clients. If the company can continue this momentum, Data Cloud could serve as a major revenue driver and strengthen Salesforce's position in AI-powered enterprise solutions. We believe that the Data Cloud platform has the potential to anchor Salesforce's revenues, which are currently witnessing a decelerating growth trend. After years of consistent double-digit revenue increases, the momentum has faded. In the first quarter, total revenues rose just 7.7% year over year. The Zacks Consensus Estimate depicts that this trend will persist, with mid-to-high single-digit growth expected for fiscal 2026 and 2027. How Rivals Stack Up Against Salesforce's Data Cloud Service Salesforce faces intensified competition from Microsoft Corporation MSFT and Snowflake Inc. SNOW in the data cloud space. Microsoft offers data services through its Azure Data platform. The company has already integrated the platform with its other productivity tools, including Power Platform, Dynamics 365 and Copilot AI, to enhance user experience and attract new clients. Many companies already use Microsoft's cloud and productivity software, making it easy to add its data services. Snowflake is another major competitor, known for its powerful cloud-based data warehouse. Unlike Salesforce, Snowflake focuses only on data, allowing companies to store, process and share large volumes easily. It also supports multiple clouds and has strong analytics tools. Salesforce's Price Performance, Valuation and Estimates Shares of Salesforce have plunged 29.1% year to date against the Zacks Computer – Software industry's growth of 20.8%. Image Source: Zacks Investment Research From a valuation standpoint, CRM trades at a forward price-to-earnings ratio of 19.77, significantly below the industry's average of 35.58. Image Source: Zacks Investment Research The Zacks Consensus Estimate for Salesforce's fiscal 2026 and 2027 earnings implies a year-over-year increase of approximately 10.8% and 11.5%, respectively. Estimates for fiscal 2026 and fiscal 2027 have been revised upward in the past 60 days. Image Source: Zacks Investment Research Salesforce currently carries a Zacks Rank #4 (Sell). You can see the complete list of today's Zacks #1 Rank (Strong Buy) stocks here. Want the latest recommendations from Zacks Investment Research? Today, you can download 7 Best Stocks for the Next 30 Days. Click to get this free report Microsoft Corporation (MSFT) : Free Stock Analysis Report Salesforce Inc. (CRM) : Free Stock Analysis Report Snowflake Inc. (SNOW) : Free Stock Analysis Report This article originally published on Zacks Investment Research ( Zacks Investment Research