logo

Iranian APT OilRig Hides Malware Config Inside Google Drive Image

ID: 274548f2-4e7f-5e3a-a7e2-93c800983897

STIX ID: report--274548f2-4e7f-5e3a-a7e2-93c800983897

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Varshini

...
...

## Executive summary A newly observed nation-state cyberespionage campaign attributed to Iranian APT-C-49 (OilRig/APT34) leverages malicious Excel macros that compile C# loaders, uses fileless memory execution and persistence via scheduled tasks, and retrieves encrypted configuration hidden by LSB steganography in Google Drive-hosted PNGs (referenced from a GitHub-hosted pointer). The campaign loads modular payloads for data theft and command execution and uses the Telegram Bot API for encrypted C2, demonstrating advanced evasion and abuse of legitimate cloud services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.