New Steganographic Campaign Distributing Multiple Malware
ID: 2e67bc9f-9bdb-5f8b-9f65-aa5ee075ae0f
STIX ID: report--2e67bc9f-9bdb-5f8b-9f65-aa5ee075ae0f
Feed Name: Seqrite Blog
Executive summary: This report analyzes a multi-stage steganographic phishing campaign that begins with a weaponized Excel exploit (CVE-2017-0199) and uses HTA/VBS scripts to download JPG images that conceal base64-encoded VB.NET injector DLLs; the DLLs perform process hollowing to deploy Remcos and AsyncRAT (remote access/infostealer capabilities). The analysis includes payload behavior, extracted configuration (C2 domains/IPs, ports, mutex, botnet name), file hashes, detection names, and MITRE ATT&CK mappings, highlighting the campaign's use of masquerading, obfuscation, and steganography to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
