logo

Tracking Threat Actors Using Images and Artifacts

ID: 52e039a0-b1a9-5623-bda9-bce52d13086c

STIX ID: report--52e039a0-b1a9-5623-bda9-bce52d13086c

Feed Name: VirusTotal Blog

Threat Score
75/100

Date Published: 2024-05-29

Date Updated: 2026-05-01

Author: Joseliyo Sánchez

...
...

This report demonstrates a methodology for hunting early-stage delivery artifacts by pivoting on embedded images and Office XML files (styles.xml and [Content_Types].xml) to identify related malicious documents and campaigns. Using VirusTotal, sandbox-dropped artifacts from PDFs, and automated image descriptions, the authors show multiple cases where image and XML reuse revealed samples and IOCs tied to actors such as APT28, Razor Tiger/SideWinder, Gamaredon, and FIN7, and provide hashes and examples to support retrohunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.