logo

Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan

ID: 166ee67c-d1f4-5155-8d4d-44d20cb53af6

STIX ID: report--166ee67c-d1f4-5155-8d4d-44d20cb53af6

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-07-08

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

A newly observed intrusion campaign attributed to APT‑C‑20 (Fancy Bear) uses a malicious Office macro dropper that writes dnxstore.dll and EdgeLogo.png, registers a hijacked CLSID to force explorer.exe to load the attacker DLL (COM hijacking), extracts shellcode from a PNG via LSB steganography, and reflectively loads an obfuscated C# remote‑control Trojan (Publish.exe) that communicates through Filen.io gateways; the report describes anti‑analysis checks, in‑memory execution, and defensive mitigations including macro hardening, COM registry monitoring, and network allowlisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.