S0231 Invoke-PSImage
Invoke-PSImage takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image. It generates a one liner for executing either from a file of from the web. Example of usage is embedding the PowerShell code from the Invoke-Mimikatz module and embed it into an image file. By calling the image file from a macro for example, the macro will download the picture and execute the PowerShell code, which in this case will dump the passwords.
| Item |
Value |
| ID |
S0231 |
| Associated Names |
|
| Type |
TOOL |
| Version |
1.1 |
| Created |
18 April 2018 |
| Last Modified |
18 October 2022 |
| Navigation Layer |
View In ATT&CK® Navigator |
Techniques Used
Groups That Use This Software
References