OilRig Hides C2 Config in Google Drive Image via LSB Steganography
ID: fe0e98dd-028d-52d3-93b7-f4396fd0934e
STIX ID: report--fe0e98dd-028d-52d3-93b7-f4396fd0934e
Feed Name: GBHackers
APT-C-49 (OilRig/APT34) deployed a sophisticated multi-stage campaign that begins with socially engineered Excel documents containing VBA macros which decode and compile C# loaders via csc.exe; those loaders fetch encrypted configuration data hidden with LSB steganography inside Google Drive images, decrypt it, and establish encrypted C2 over the Telegram Bot API to dynamically load modules for persistence, file transfer, command execution and program execution. The report attributes the operation to an Iranian state-sponsored actor based on coding similarities and Persian-language comments, and recommends monitoring cloud storage access patterns, suspicious macro-enabled documents, and anomalous use of legitimate tools like csc.exe to detect and mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
