logo

OilRig Hides C2 Config in Google Drive Image via LSB Steganography

ID: fe0e98dd-028d-52d3-93b7-f4396fd0934e

STIX ID: report--fe0e98dd-028d-52d3-93b7-f4396fd0934e

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Mayura Kathir

...
...

APT-C-49 (OilRig/APT34) deployed a sophisticated multi-stage campaign that begins with socially engineered Excel documents containing VBA macros which decode and compile C# loaders via csc.exe; those loaders fetch encrypted configuration data hidden with LSB steganography inside Google Drive images, decrypt it, and establish encrypted C2 over the Telegram Bot API to dynamically load modules for persistence, file transfer, command execution and program execution. The report attributes the operation to an Iranian state-sponsored actor based on coding similarities and Persian-language comments, and recommends monitoring cloud storage access patterns, suspicious macro-enabled documents, and anomalous use of legitimate tools like csc.exe to detect and mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.