Invoke-PSImage is a PowerShell-based steganographic tool used to embed payload data, specifically PowerShell scripts, within image files, including PNG images and newly created image files. The provided content describes it as a tool that encodes PowerShell script content into the pixels of a PNG/image file to conceal the payload. This behavior aligns it with image-based payload hiding and embedded-payload tradecraft used to evade detection and stage follow-on execution. The content does not provide a specific threat actor exclusively associated with Invoke-PSImage, but it places the tool in the broader context of malware and intrusion activity that uses steganography and embedded payloads in images. No specific infection vector, targeted industry, or indicators of compromise are directly provided beyond its use of PNG/image files as the carrier for embedded PowerShell payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Can embed payload data within a new image file.
PowerShell-based tool used to embed payload data into image files (steganography) for delivery/execution workflows.
PowerShell-based steganography tool used to embed PowerShell scripts into PNG pixel data for covert delivery/execution.
PowerShell tool used to embed payload data within image files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.