logo

Modeling Malicious Code: Hacking in 3D

ID: cfba7a5d-e68a-5107-a322-b0586c88d3ae

STIX ID: report--cfba7a5d-e68a-5107-a322-b0586c88d3ae

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This research demonstrates a stealthy technique to hide and deliver shellcode by embedding payload bytes as coordinate values inside the XML of `*.3mf` (ZIP-based) 3D model files, then reassembling and executing the shellcode (example uses an `*.lnk` inside a mounted `*.iso` to launch a Havoc Framework agent). The report covers file structure analysis, a helper script for embedding/extraction, execution methods, detection challenges, and defensive recommendations such as strict attachment filtering and monitoring of containerized and script-based execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.