Researchers at the Trellix Advanced Research Center have uncovered a sophisticated PureRAT campaign that weaponizes innocent-looking PNG image files to secretly deliver fully fileless malware payloads, bypassing conventional endpoint defenses through a complex, multi-stage infection chain.
The campaign demonstrates how advanced threat actors are blending steganography, in-memory execution, and living-off-the-land techniques to evade detection at every step of the attack.
A Multi-Stage Infection Chain Beginning With a Simple Shortcut
The attack begins deceptively simply a malicious Windows shortcut (.LNK) file triggers a hidden PowerShell command that downloads a heavily obfuscated VBS loader from the actor-controlled domain hxxps://crixup[.]com. This VBScript loader is the engine of the infection.
It copies itself to C:\Users\Public\Downloads\ under a randomized filename, then uses Windows Management Instrumentation (WMI) to silently launch a new hidden process with ShowWindow = 0, making it completely invisible to the victim.
To ensure it survives reboots, the script registers a Windows Task Scheduler entry that runs every minute indefinitely, ensuring continuous execution on the compromised host.
After de-obfuscation, what appears to be a junk data array in the VBScript is revealed to be a fully functional embedded PowerShell script the next stage of the attack.

That PowerShell loader attempts to connect to the same C2 domain and downloads two PNG image files: 0xptimized_MSI.png and GeneratedPay.png.
These are not ordinary images. Encoded within unique delimiter strings in the PNG files are Base64-Encrypted, reversed, and character-substituted malicious PE files a classic steganography technique designed to slip past signature-based detection tools.

Once the payload is extracted from the PNG, it is loaded directly into PowerShell memory using [System.Reflection.Assembly]:: Load(), never touching the disk.
This fileless execution technique is the campaign’s defining characteristic, rendering traditional file-scanning defenses largely ineffective.
UAC Bypass, Anti-VM Checks, and Process Hollowing Into Msbuild.exe
To escalate privileges without alerting the Trellix user, the malware performs a UAC bypass via the legitimate Windows binary cmstp.exe.

It generates a temporary .inf configuration file containing a PowerShell command that turns off all UAC prompts by modifying the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System registry key.
It then launches cmstp.exe /au and programmatically sends an Enter keypress to the resulting elevation dialog using Windows API calls fully automating the privilege escalation without any user interaction.
Indicators of Compromise (IOCs)
| Type | Value |
|---|---|
| SHA256 (.LNK) | 7d22c61e8aafc9a2a812cafe7720922ab12d770e5af7d92527d9b0dbd6e10f30 |
| SHA256 (VBS Loader) | 96b4713c6b9e5283f9d2f570a51edce66fc44ced2ae130b65dbe1326690a27eb |
| SHA256 (0xptimized_MSI.png) | 40bd37eba7f9a56516c96092d5c6d50937fc4df00baf79155ada9d1673389830 |
| SHA256 (GeneratedPay.png) | 121ae6c664aaef9ed2e44ed04c66e1cabcb00295c48289afd9e23126fc6edadf |
Security teams are advised to monitor for unauthorized scheduled task creation, restrict execution of VBS and PowerShell scripts via execution policy controls, and block the listed C2 indicators at the network perimeter.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.