logo

New Steganographic Campaign Distributing Multiple Malware

ID: 2e67bc9f-9bdb-5f8b-9f65-aa5ee075ae0f

STIX ID: report--2e67bc9f-9bdb-5f8b-9f65-aa5ee075ae0f

Feed Name: Seqrite Blog

Threat Score
70/100

Date Published: 2025-03-17

Date Updated: 2026-04-30

Author: Kirti Kshatriya

...
...

Executive summary: This report analyzes a multi-stage steganographic phishing campaign that begins with a weaponized Excel exploit (CVE-2017-0199) and uses HTA/VBS scripts to download JPG images that conceal base64-encoded VB.NET injector DLLs; the DLLs perform process hollowing to deploy Remcos and AsyncRAT (remote access/infostealer capabilities). The analysis includes payload behavior, extracted configuration (C2 domains/IPs, ports, mutex, botnet name), file hashes, detection names, and MITRE ATT&CK mappings, highlighting the campaign's use of masquerading, obfuscation, and steganography to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.