Skip to content
Photonews Logo Photonews logo
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Azad Jammu Kashmir
    • Balochistan
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
    Olivia Wilde Trailer Gregg Araki Thriller I Want Your Sex Trailer Shows Olivia
    Videos

    Olivia Wilde Trailer Shows Gregg Araki Thriller I Want Your Sex Trailer Shows Olivia

    June 11, 2026 1 Min Read
    Alia Bhatt Alpha teaser shows the actor entering action mode in YRF’s female-led spy thriller.
    Videos

    Alia Bhatt Alpha Teaser Shows Bobby Deol Training Her

    June 10, 2026 1 Min Read
    Fire Point co-owner Denys Shtilerman speaks during an interview with journalist Alesia Batsman.
    Videos

    Ukraine Nuclear Weapons Claim Made By Fire Point Co-Owner

    June 5, 2026 2 Min Read
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Reading: Weaponised JPEG File Used To Deploy Windows Malware
PhotoNews PakistanPhotoNews Pakistan
Font ResizerAa
Search
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Have an existing account? Sign In
Follow US
© 2022 Photonews. All Rights Reserved.
A futuristic cybersecurity graphic shows the Windows logo and layered transparent panels with data streams, code, and malware-related icons.
PhotoNews Pakistan > Tech > Weaponised JPEG File Used To Deploy Windows Malware
Tech

Weaponised JPEG File Used To Deploy Windows Malware

Web Desk
By Web Desk Published May 13, 2026 1 Min Read
Share
A futuristic cybersecurity graphic shows the Windows logo and layered transparent panels with data streams, code, and malware-related icons. Image Credit: Hoplon InfoSec
SHARE

CYFIRMA researchers said attackers are using a weaponised JPEG file to install trojanised ScreenContact remote-access malware in a new Windows campaign called “Operation SilentCanvas.”

The attack starts with a file named “sysupdate.jpeg,” distributed through phishing emails, fake software updates or deceptive file-sharing links, the source content said.

Despite its .jpeg extension, the file contains no image data. It carries a malicious PowerShell script that creates a hidden “C:\systems” folder and downloads the malware.

A malicious Hugging Face repository impersonating OpenAI's Privacy Filter model was downloaded over 244,000 times before the platform pulled it.

If you downloaded it, hackers got passwords and crypto wallet seed phrases from your browsers. https://t.co/6fICSDsDWi

— Decrypt (@DecryptMedia) May 13, 2026

CYFIRMA said the malware avoids detection by dynamically rebuilding commands, running additional files in memory, and using Microsoft’s .NET compiler tool, “csc.exe,” to create custom payloads on infected computers.

Read: 149 Million Passwords Exposed in Infostealer Data Leak, Google Confirms

The campaign also abuses “ComputerDefaults.exe,” a trusted Windows binary, to bypass User Account Control and gain administrative privileges without triggering a visible security prompt.

After installation, attackers can remotely monitor the screen, record video, capture microphone audio, log keystrokes and transfer files.

CYFIRMA advised defenders to monitor or restrict “csc.exe,” “cvtres.exe” and “ComputerDefaults.exe,” enforce controls on remote-access tools and isolate systems showing unexpected ScreenContact activity.

TAGGED:Featured
Share This Article
Facebook Twitter Pinterest Whatsapp Whatsapp LinkedIn Email Copy Link Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Advertisement

Recent Posts

Islamabad Memorandum ended US-Iran hostilities, opened 60-day nuclear talks and drew criticism over sanctions relief.

US Iran Talks Set for Doha, Pakistan Tracks

United Nations emblem displayed on a gold wall inside the UN General Assembly Hall.

UN Charter Day Speech Urges Stronger Cooperation

Cape Verde players celebrating after reaching the World Cup knockout stage for the first time.

How Cape Verde Stunned World Cup to Set Up Argentina Tie

Post Archives

More Popular from Photonews

BTS members V and Jungkook move through Incheon International Airport, where V shared headphones with Jungkook before a flight to Madrid.
Entertainment

BTS V Jungkook Airport Moment Draws Fan Attention

2 Min Read
Punjab budget debate ended as Mujtaba Shujaur Rehman defended allocations, citing Rs556bn for south Punjab and Health Card funds.
PakistanPunjab

Punjab Budget Debate Ends With Govt Defence

1 Min Read
Scientific chart showing Japan seismic shift data after the 2011 magnitude 9.0 earthquake.
Offbeat

Japan Seismic Shift Traced to Earth’s Core Wave

2 Min Read
Sindh

Sindh Ashura Processions Continue Amid Tight Security

Karachi: Sindh Ashura security measures were tightened on Friday, June 26, 2026, after Inspector General of…

June 26, 2026
Pakistan

Islamabad DIG Jailed For One Month In PTI Case

Islamabad: Islamabad DIG jailed for one month on Tuesday after an Anti-Terrorism Court found Muhammad Jawad…

June 23, 2026
Khyber Pakhtunkhwa

Amir Muqam Demands Govt to Withdraw New Taxes on FATA, PATA

FATA PATA taxes should be withdrawn, Federal Minister for Kashmir Affairs Engineer Amir Muqam said on…

June 23, 2026
Sports

France Beat Norway 4-1 as Dembélé Scores Hat-Trick

France beat Norway 4-1 at Gillette Stadium near Boston on Friday as Ousmane Dembélé scored a…

June 27, 2026
PhotoNews Pakistan

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

    Categories

    • World
    • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir

     

    • Top News
    • Business
    • Entertainment
    • Sports
    • Videos
    • Tech
    • Offbeat
    • Blog
    • About Us
    • Privacy Policy
    • Code of Ethics & Editorial Standards

    © 2026 Phototnews
    All Rights Reserved.

    Welcome Back!

    Sign in to your account

    Lost your password?