logo

PixyNetLoader Malware Analysis: How APT28 Hides Payloads Inside PNG Files

ID: 4e1401e4-bcdb-5b89-a02a-e73b50867382

STIX ID: report--4e1401e4-bcdb-5b89-a02a-e73b50867382

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Do Son

...
...

**Executive summary:** PixyNetLoader is a DLL-based loader attributed to APT28 that hides encrypted Covenant Grunt payloads in PNG files using least-significant-bit steganography, is delivered via an Office document exploiting CVE-2026-21509, and employs COM persistence and FILEN cloud C2; researchers identified four code families (Family C being the most stealthy), produced YARA rules and a decryption script, and recommend hunting for companion PNGs, COM registry keys, and unexpected FILEN traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.