{"id":204617,"date":"2022-10-03T11:44:15","date_gmt":"2022-10-03T09:44:15","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=204617"},"modified":"2025-07-01T20:24:44","modified_gmt":"2025-07-02T03:24:44","slug":"scammers-hiding-malware-windows-logo","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/scammers-hiding-malware-windows-logo\/","title":{"rendered":"Scammers have been hiding malware in the Windows logo!"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Malware seems to be everywhere these days with scammers hiding it in everything from fake job offers to LinkedIn Smart Links. Today, however, we have news of malware being pumped into even the most inconspicuous of places, the Windows logo itself. It seems that malicious actors have shipping out <strong>dangerous malware hidden in image files and that even the Windows logo has been affected in this manner<\/strong>. Here is what you need to know.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Windows 11\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-xl,f_auto\/p\/3a83edc2-8bcb-4baa-8fbe-3ddcf458c1a4\/1709716978\/windows-11-win11icon.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Windows 11<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/windows-11.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download Now<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/windows-11.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity experts at Symantec have discovered a new way that threat actors have been trying to catch out unsuspecting victims. <strong>The malicious method is called steganograp<\/strong>hy and involves hiding malware code into images.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the Symantec <a href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/witchetty-steganography-espionage\" target=\"_blank\" rel=\"noreferrer noopener\">report<\/a> the campaign, which is being perpetrated by a cybercriminal gang called Witchetty<strong> hides an XOR-encrypted backdoor malware in a bitmap image of an old Windows logo<\/strong>. Interestingly, the compromised file is hosted on a cloud service that wouldn\u2019t normally be flagged as being suspicious, which is what allows it to evade security scanners.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The XOR-encrypted backdoor <strong>allows the scammers<\/strong> <strong>to perform various actions,<\/strong> which will cause the victim harm including altering and editing files and folders, starting and terminating processes, downloading further infected files onto the device, stealing files and documents, and even messing around with the Windows Registry.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Incredibly, it seems like this type of attack<strong> has successfully targeted several institutions<\/strong> including several governments in the Middle East and even the South African Stock Exchange.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Again, however, this is just another example of why <strong>you need to be more careful than ever these days when you are using your computer and online.<\/strong> With malicious files even infiltrating mundane elements of our digital experience such as Windows logos and basic image files, we really do need to be up to date with how to spot these types of scams and prevent them ending up on our devices. To help you do this we recommend consulting with our <a href=\"https:\/\/en.softonic.com\/articles\/how-to-detect-fakescam-emails-and-avoid-phishing-attacks-hi-res-version\" target=\"_blank\" rel=\"noreferrer noopener\">guide to spotting phishing scams and fake emails<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malware seems to be everywhere these days with scammers hiding it in everything from fake job offers to LinkedIn Smart Links. Today, however, we have news of malware being pumped into even the most inconspicuous of places, the Windows logo itself. It seems that malicious actors have shipping out dangerous malware hidden in image files &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/scammers-hiding-malware-windows-logo\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Scammers have been hiding malware in the Windows logo!&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9073,"featured_media":204660,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[3149],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-204617","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionwindows-11"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/204617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=204617"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/204617\/revisions"}],"predecessor-version":[{"id":323100,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/204617\/revisions\/323100"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/204660"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=204617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=204617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=204617"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=204617"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=204617"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=204617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}