PixyNetLoader Malware Analysis: How APT28 Hides Payloads Inside PNG Files
ID: 4e1401e4-bcdb-5b89-a02a-e73b50867382
STIX ID: report--4e1401e4-bcdb-5b89-a02a-e73b50867382
Feed Name: securityonline.info
**Executive summary:** PixyNetLoader is a DLL-based loader attributed to APT28 that hides encrypted Covenant Grunt payloads in PNG files using least-significant-bit steganography, is delivered via an Office document exploiting CVE-2026-21509, and employs COM persistence and FILEN cloud C2; researchers identified four code families (Family C being the most stealthy), produced YARA rules and a decryption script, and recommend hunting for companion PNGs, COM registry keys, and unexpected FILEN traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
