PNGLoad
- First seen
- 2022-09-01 00:00:00
- Malware type
- loader
- Profile updated
- 2026-07-07 13:05:27
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
According to ESET Research, PNGLoad is a second-stage payload deployed by Worok on compromised systems and loaded either by CLRLoad or PowHeartBeat. PNGLoad has capabilities to download and execute additional payloads from a C&C server, which is likely how the attackers have deployed PNGLoad on systems compromised with PowHeartBeat. PNGLoad is a loader that uses bytes from PNG files to create a payload to execute. It is a 64-bit .NET executable - obfuscated with .NET Reactor - that masquerades as legitimate software.
Reports & references
- ESET — Worok Big Picture (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Png Load (report)