Malware hid in image exif metadata

By

Picture this.

Malware has been discovered hiding within images in a bid to mask attacks.

Malware hid in image exif metadata

Sucuri researcher Peter Gramantik found the compromised but working images on a small number of sites.

He said attackers had preserved the image by storing malware within the image exif metadata, which contained time and geo location information. 

PHP code then executed the malicious payload.

"The backdoor is divided into two parts. The first part is a mix of the exif_read_data function to read the image headers and the preg_replace function to execute the content, chief technology officer Daniel Cid wrote in a post.

"Both functions are harmless by themselves. Exif_read_data is commonly used to read images and preg_replace to replace the content of strings. However, preg_replace has a hidden and tricky option where if you pass the “/e” modifier it will execute the content (eval), instead of just searching/replacing."

Organisations could defend against the attack by white-listing only PHP scripts that support necessary business needs, or by removing exif data from images, Lumension forensics analyst Paul Henry said.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Service NSW centralises security, networking in mammoth CloudOps overhaul

Service NSW centralises security, networking in mammoth CloudOps overhaul

VicRoads to phase out passwords in favour of passkeys

VicRoads to phase out passwords in favour of passkeys

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Log In

  |  Forgot your password?