logo

New Stealthy .NET Malware Concealing Malicious Payloads in Bitmap Resources

ID: 25833588-964b-526b-b5a9-1d6bfbbcb9fb

STIX ID: report--25833588-964b-526b-b5a9-1d6bfbbcb9fb

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-05-09

Date Updated: 2026-05-05

Author: Mandvi

...
...

This report documents a malspam-driven campaign (250+ emails) distributing 32-bit .NET executables that hide successive loader stages inside bitmap resources via steganography; the chained loaders, employing metadata/control-flow obfuscation and string encryption, decrypt and execute final payloads such as Agent Tesla, XLoader, or Remcos RAT for credential theft and remote access. The analysis includes a detailed infection workflow, recommended dynamic analysis techniques (intercepting .NET ResourceManager and assembly loading), and comprehensive IOCs (SHA-256 hashes, C2 endpoints, sender/receiver emails and credentials) to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.