Skip to content
Photonews Logo Photonews logo
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Azad Jammu Kashmir
    • Balochistan
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
    GA-20 and Grammy-winning musician Charlie Musselwhite perform “I Can’t Hold Out” during CBS Saturday Morning’s Saturday Sessions on August 1.
    Videos

    GA-20 and Charlie Musselwhite Perform ‘I Can’t Hold Out’

    August 2, 2026 1 Min Read
    Ricky Gervais Alley Cats official Netflix trailer
    Videos

    Ricky Gervais ‘Alley Cats’ Trailer Sets August 7 Debut

    July 23, 2026 2 Min Read
    Sam Fender Olivia Dean break UK chart record with Rein Me In after 16 weeks at No. 1.
    Videos

    Sam Fender, Olivia Dean Break 30-Year UK Chart Record

    July 12, 2026 2 Min Read
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Reading: Weaponised JPEG File Used To Deploy Windows Malware
PhotoNews PakistanPhotoNews Pakistan
Font ResizerAa
Search
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Have an existing account? Sign In
Follow US
© 2022 Photonews. All Rights Reserved.
A futuristic cybersecurity graphic shows the Windows logo and layered transparent panels with data streams, code, and malware-related icons.
PhotoNews Pakistan > Tech > Weaponised JPEG File Used To Deploy Windows Malware
Tech

Weaponised JPEG File Used To Deploy Windows Malware

Web Desk
By Web Desk Published May 13, 2026 1 Min Read
Share
A futuristic cybersecurity graphic shows the Windows logo and layered transparent panels with data streams, code, and malware-related icons. Image Credit: Hoplon InfoSec
SHARE

CYFIRMA researchers said attackers are using a weaponised JPEG file to install trojanised ScreenContact remote-access malware in a new Windows campaign called “Operation SilentCanvas.”

The attack starts with a file named “sysupdate.jpeg,” distributed through phishing emails, fake software updates or deceptive file-sharing links, the source content said.

Despite its .jpeg extension, the file contains no image data. It carries a malicious PowerShell script that creates a hidden “C:\systems” folder and downloads the malware.

A malicious Hugging Face repository impersonating OpenAI's Privacy Filter model was downloaded over 244,000 times before the platform pulled it.

If you downloaded it, hackers got passwords and crypto wallet seed phrases from your browsers. https://t.co/6fICSDsDWi

— Decrypt (@DecryptMedia) May 13, 2026

CYFIRMA said the malware avoids detection by dynamically rebuilding commands, running additional files in memory, and using Microsoft’s .NET compiler tool, “csc.exe,” to create custom payloads on infected computers.

Read: 149 Million Passwords Exposed in Infostealer Data Leak, Google Confirms

The campaign also abuses “ComputerDefaults.exe,” a trusted Windows binary, to bypass User Account Control and gain administrative privileges without triggering a visible security prompt.

After installation, attackers can remotely monitor the screen, record video, capture microphone audio, log keystrokes and transfer files.

CYFIRMA advised defenders to monitor or restrict “csc.exe,” “cvtres.exe” and “ComputerDefaults.exe,” enforce controls on remote-access tools and isolate systems showing unexpected ScreenContact activity.

TAGGED:Featured
Share This Article
Facebook Twitter Pinterest Whatsapp Whatsapp LinkedIn Email Copy Link Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Advertisement

Bank Alfalah Pehchan account

Recent Posts

University of Karachi professor Muhammad Arif Khan Saqi after alleged road-rage assault in Safoora Goth

Karachi Professor Assault: Three Suspects Detained by Police

Hormuz blockade removed by the US after Iran talks, as Trump cited concessions on inspections and released assets.

Iran Says It Can Strike US Warships Enforcing Blockade

US strike Iran says hit Bampur barracks killed seven military personnel, as Tehran’s army vowed a decisive response.

Iran Threatened ​the US with “Economic Warfare”

Post Archives

More Popular from Photonews

Karachi digital parking system being installed at a KMC parking site.
Sindh

Karachi Digital Parking System Nears Launch at KMC Lots

2 Min Read
Sahito-1 gasfield production facility in Khairpur as OGDCL injects gas into SSGCL network.
SindhWriting

OGDCL Bobi-11 Discovery Targets 1,000 Barrels a Day

2 Min Read
Mackenzie Shirilla pictured in a courtroom and correctional facility images.
World

TV Court Voted 5-2, Mackenzie Shirilla Appeal Rejected

2 Min Read
World

Pentagon Testosterone Screening Starts for Troops 30+

WASHINGTON, United States: Pentagon testosterone screening will begin immediately for male active-duty and reserve service members…

September 3, 2026
Sports

Premier League Transfer Premium Hits Nearly £20 Million

LONDON, United Kingdom: The Premier League transfer premium reached nearly £20 million this summer, with clubs…

September 4, 2026
World

USS Abraham Lincoln Docks in Thailand After 286 Days at Sea

BANGKOK, Thailand: The USS Abraham Lincoln docked at Laem Chabang in eastern Thailand on September 2…

September 3, 2026
Tech

Musk AI Prediction Sees Superhuman Digital Skills by 2027

Elon Musk’s AI prediction says artificial intelligence could perform virtually any digital task at a superhuman…

September 3, 2026
PhotoNews Pakistan

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

    Categories

    • World
    • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir

     

    • Top News
    • Business
    • Entertainment
    • Sports
    • Videos
    • Tech
    • Offbeat
    • Blog
    • About Us
    • Privacy Policy
    • Code of Ethics & Editorial Standards

    © 2026 Phototnews
    All Rights Reserved.

    Welcome Back!

    Sign in to your account

    Lost your password?