Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan
ID: 166ee67c-d1f4-5155-8d4d-44d20cb53af6
STIX ID: report--166ee67c-d1f4-5155-8d4d-44d20cb53af6
Feed Name: GBHackers
A newly observed intrusion campaign attributed to APT‑C‑20 (Fancy Bear) uses a malicious Office macro dropper that writes dnxstore.dll and EdgeLogo.png, registers a hijacked CLSID to force explorer.exe to load the attacker DLL (COM hijacking), extracts shellcode from a PNG via LSB steganography, and reflectively loads an obfuscated C# remote‑control Trojan (Publish.exe) that communicates through Filen.io gateways; the report describes anti‑analysis checks, in‑memory execution, and defensive mitigations including macro hardening, COM registry monitoring, and network allowlisting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
