logo

Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources

ID: a888b233-ebdb-5f61-9849-32068f62205c

STIX ID: report--a888b233-ebdb-5f61-9849-32068f62205c

Feed Name: Palo Alto Networks Unit 42

Threat Score
72/100

Date Published: 2025-05-09

Date Updated: 2026-04-28

Author: Lee Wei Yeong and Alex Armstrong

...
...

**Executive Summary:** This Unit 42 analysis details a multi-stage malspam campaign (late 2024–early 2025) that embeds malicious payloads within bitmap resources of otherwise benign 32-bit .NET applications using steganography and layered loaders to deliver info-stealers and RATs (Agent Tesla, XLoader, Remcos); the report reconstructs the unpacking chain, provides SHA-256 hashes, C2 domains and SMTP exfiltration credentials, and recommends detection/mitigation approaches such as intercepting ResourceManager and Assembly.Load calls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.