Iranian APT OilRig Hides Malware Config Inside Google Drive Image
ID: 274548f2-4e7f-5e3a-a7e2-93c800983897
STIX ID: report--274548f2-4e7f-5e3a-a7e2-93c800983897
Feed Name: Cyber Press
## Executive summary A newly observed nation-state cyberespionage campaign attributed to Iranian APT-C-49 (OilRig/APT34) leverages malicious Excel macros that compile C# loaders, uses fileless memory execution and persistence via scheduled tasks, and retrieves encrypted configuration hidden by LSB steganography in Google Drive-hosted PNGs (referenced from a GitHub-hosted pointer). The campaign loads modular payloads for data theft and command execution and uses the Telegram Bot API for encrypted C2, demonstrating advanced evasion and abuse of legitimate cloud services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
