Modeling Malicious Code: Hacking in 3D
ID: cfba7a5d-e68a-5107-a322-b0586c88d3ae
STIX ID: report--cfba7a5d-e68a-5107-a322-b0586c88d3ae
Feed Name: TrustedSec blog
This research demonstrates a stealthy technique to hide and deliver shellcode by embedding payload bytes as coordinate values inside the XML of `*.3mf` (ZIP-based) 3D model files, then reassembling and executing the shellcode (example uses an `*.lnk` inside a mounted `*.iso` to launch a Havoc Framework agent). The report covers file structure analysis, a helper script for embedding/extraction, execution methods, detection challenges, and defensive recommendations such as strict attachment filtering and monitoring of containerized and script-based execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
