OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography
ID: 655c4bcb-4d94-5b1c-9739-22aae45de06a
STIX ID: report--655c4bcb-4d94-5b1c-9739-22aae45de06a
Feed Name: cybersecurityNews.com
Threat Score
This report details an OilRig (APT34/Helix Kitten) campaign that used a malicious macro-enabled Excel file to compile a C# loader which retrieved a GitHub pointer to a Google Drive PNG containing LSB-steganography hidden, encrypted C2 configuration; the loader decoded the configuration (Telegram bot token, chat ID, and module URLs) and loaded five in-memory modules for persistence and data exfiltration, leveraging GitHub, Google Drive, and Telegram to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
