ATT&CKSoftwareInvoke-PSImage

Invoke-PSImage

S0231

Tool.View on attack.mitre.org

About this tool

Invoke-PSImage takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image. It generates a one liner for executing either from a file of from the web. Example of usage is embedding the PowerShell code from the Invoke-Mimikatz module and embed it into an image file. By calling the image file from a macro for example, the macro will download the picture and execute the PowerShell code, which in this case will dump the passwords.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1027.003
Steganography

Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file.

T1027.009
Embedded Payloads

Invoke-PSImage can be used to embed payload data within a new image file.

Groups that use it1

Campaigns0

None recorded.

References1

  1. GitHub Invoke-PSImage Open source
    Adams, B. (2017, December 17). Invoke-PSImage. Retrieved April 10, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.