Favicon Trojans: Executable Steganography Via Ico Alpha Channel Exploitation

📅 2025-07-11
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work introduces an executable steganography technique leveraging the Alpha channel of ICO favicon files to embed self-decompressing JavaScript payloads—enabling visually lossless, request-free covert execution. Methodologically, compressed JavaScript code is encoded into the Alpha channel via least-significant-bit (LSB) steganography; subsequent in-memory decompression and execution are achieved through Canvas pixel reading, ensuring complete silence, zero disk I/O, and evasion of Content Security Policy (CSP) and mainstream antivirus detection. The key contribution lies in the first demonstration of executable code concealment within the Alpha channel of browser-default-loaded favicons, mapping multi-stage MITRE ATT&CK tactics onto a single-line JavaScript payload—thereby exposing the erosion of boundaries between static resources and executable content. Evaluation shows that a 64×64 ICO file can host 0.8 KB of compressed JavaScript and execute successfully across major browsers; exploiting ~294 billion daily favicon requests globally, this approach establishes a highly stealthy, low-detectability attack surface.

Technology Category

Computer Vision: Adversarial Attacks & RobustnessApplication Domains: SecurityNatural Language Processing: Fact-Checking / Misinformation Detection (NLP Focus)

Application Category

Responsible Web: Human-perceived consequences of algorithmic deployment on the webSecurity and Privacy: Large-scale security measurementsGraph Algorithms and Modeling for the Web: Efficient manipulation of static and dynamic Web-related graphs
📝 Abstract
This paper presents a novel method of executable steganography using the alpha transparency layer of ICO image files to embed and deliver self-decompressing JavaScript payloads within web browsers. By targeting the least significant bit (LSB) of non-transparent alpha layer image values, the proposed method successfully conceals compressed JavaScript code inside a favicon image without affecting visual fidelity. Global web traffic loads 294 billion favicons daily and consume 0.9 petabytes of network bandwidth. A proof-of-concept implementation demonstrates that a 64x64 ICO image can embed up to 512 bytes uncompressed, or 0.8 kilobyte when using lightweight two-fold compression. On page load, a browser fetches the favicon as part of standard behavior, allowing an embedded loader script to extract and execute the payload entirely in memory using native JavaScript APIs and canvas pixel access. This creates a two-stage covert channel requiring no additional network or user requests. Testing across multiple browsers in both desktop and mobile environments confirms successful and silent execution of the embedded script. We evaluate the threat model, relate it to polymorphic phishing attacks that evade favicon-based detection, and analyze evasion of content security policies and antivirus scanners. We map nine example MITRE ATT&CK Framework objectives to single line JavaScript to execute arbitrarily in ICO files. Existing steganalysis and sanitization defenses are discussed, highlighting limitations in detecting or neutralizing alpha-channel exploits. The results demonstrate a stealthy and reusable attack surface that blurs traditional boundaries between static images and executable content. Because modern browsers report silent errors when developers specifically fail to load ICO files, this attack surface offers an interesting example of required web behaviors that in turn compromise security.
Problem

Research questions and friction points this paper is trying to address.

Hiding executable JavaScript in favicon alpha channels
Evading detection via favicon-based steganography
Exploiting browser behavior for covert payload execution
Innovation

Methods, ideas, or system contributions that make the work stand out.

Uses ICO alpha channel for steganography
Embeds JavaScript in favicon LSB
Executes payload via browser APIs
🔎 Similar Papers
No similar papers found.