Skip to content
Photonews Logo Photonews logo
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Azad Jammu Kashmir
    • Balochistan
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
    Olivia Wilde Trailer Gregg Araki Thriller I Want Your Sex Trailer Shows Olivia
    Videos

    Olivia Wilde Trailer Shows Gregg Araki Thriller I Want Your Sex Trailer Shows Olivia

    June 11, 2026 1 Min Read
    Alia Bhatt Alpha teaser shows the actor entering action mode in YRF’s female-led spy thriller.
    Videos

    Alia Bhatt Alpha Teaser Shows Bobby Deol Training Her

    June 10, 2026 1 Min Read
    Fire Point co-owner Denys Shtilerman speaks during an interview with journalist Alesia Batsman.
    Videos

    Ukraine Nuclear Weapons Claim Made By Fire Point Co-Owner

    June 5, 2026 2 Min Read
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Reading: Weaponised JPEG File Used To Deploy Windows Malware
PhotoNews PakistanPhotoNews Pakistan
Font ResizerAa
Search
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Have an existing account? Sign In
Follow US
© 2022 Photonews. All Rights Reserved.
A futuristic cybersecurity graphic shows the Windows logo and layered transparent panels with data streams, code, and malware-related icons.
PhotoNews Pakistan > Tech > Weaponised JPEG File Used To Deploy Windows Malware
Tech

Weaponised JPEG File Used To Deploy Windows Malware

Web Desk
By Web Desk Published May 13, 2026 1 Min Read
Share
A futuristic cybersecurity graphic shows the Windows logo and layered transparent panels with data streams, code, and malware-related icons. Image Credit: Hoplon InfoSec
SHARE

CYFIRMA researchers said attackers are using a weaponised JPEG file to install trojanised ScreenContact remote-access malware in a new Windows campaign called “Operation SilentCanvas.”

The attack starts with a file named “sysupdate.jpeg,” distributed through phishing emails, fake software updates or deceptive file-sharing links, the source content said.

Despite its .jpeg extension, the file contains no image data. It carries a malicious PowerShell script that creates a hidden “C:\systems” folder and downloads the malware.

A malicious Hugging Face repository impersonating OpenAI's Privacy Filter model was downloaded over 244,000 times before the platform pulled it.

If you downloaded it, hackers got passwords and crypto wallet seed phrases from your browsers. https://t.co/6fICSDsDWi

— Decrypt (@DecryptMedia) May 13, 2026

CYFIRMA said the malware avoids detection by dynamically rebuilding commands, running additional files in memory, and using Microsoft’s .NET compiler tool, “csc.exe,” to create custom payloads on infected computers.

Read: 149 Million Passwords Exposed in Infostealer Data Leak, Google Confirms

The campaign also abuses “ComputerDefaults.exe,” a trusted Windows binary, to bypass User Account Control and gain administrative privileges without triggering a visible security prompt.

After installation, attackers can remotely monitor the screen, record video, capture microphone audio, log keystrokes and transfer files.

CYFIRMA advised defenders to monitor or restrict “csc.exe,” “cvtres.exe” and “ComputerDefaults.exe,” enforce controls on remote-access tools and isolate systems showing unexpected ScreenContact activity.

TAGGED:Featured
Share This Article
Facebook Twitter Pinterest Whatsapp Whatsapp LinkedIn Email Copy Link Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Advertisement

Recent Posts

Philippines Earthquake Uplift exposing coral reefs and dead marine life after the Mindanao quake

Philippines Earthquake Uplift Exposes Coral, Kills Marine Life

Jennifer Lopez Knicks reaction video after New York won the NBA title against the San Antonio Spurs.

Jennifer Lopez Knicks Reaction Marks NBA Title Win

Composite image of US President Donald Trump and Iran’s Supreme Leader Mojtaba Khamenei against the US and Iranian flags.

US Iran Memorandum Covers Hormuz, Sanctions And Nuclear Deal

Post Archives

More Popular from Photonews

Marissa Ayers Miami Swim Week photos draw a social media.
Entertainment

Marissa Ayers Miami Swim Week Photos Draw Livvy Dunne Reply

1 Min Read
Split-screen image showing an Iranian missile launch and fiery trails in the night sky from IRGC footage.
World

Iran IRGC Releases Footage of Missile Strikes on US Targets

2 Min Read
GB election results process continues as Gilgit-Baltistan Election Commission hears petitions and orders Skardu recount.
Gilgit - Baltistan

GB Election Results To Be Notified Within 14 Days

2 Min Read
Tech

Artemis III Crew Named For 2027 NASA Moon Test

Washington: NASA named the Artemis III crew for a 2027 mission that will test systems needed…

June 10, 2026
Top NewsWorld

Trump Iran Strike Threat Targets Oil Sites, Kharg Island

Washington: President Donald Trump said the United States would hit Iran “very hard” on Thursday night.…

June 11, 2026
World

US strike inside Venezuela Tren de Aragua Leader Killed

Trump said on Truth Social that the United States Southern Command carried out a “swift and…

June 13, 2026
Punjab

Muharram Cyber Patrol Blocks 5,000 Online Pages

Lahore, Punjab: The Punjab government launched a Muharram cyber patrol and blocked more than 5,000 social…

June 9, 2026
PhotoNews Pakistan

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

    Categories

    • World
    • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir

     

    • Top News
    • Business
    • Entertainment
    • Sports
    • Videos
    • Tech
    • Offbeat
    • Blog
    • About Us
    • Privacy Policy
    • Code of Ethics & Editorial Standards

    © 2026 Phototnews
    All Rights Reserved.

    Welcome Back!

    Sign in to your account

    Lost your password?