Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources
ID: a888b233-ebdb-5f61-9849-32068f62205c
STIX ID: report--a888b233-ebdb-5f61-9849-32068f62205c
Feed Name: Palo Alto Networks Unit 42
**Executive Summary:** This Unit 42 analysis details a multi-stage malspam campaign (late 2024–early 2025) that embeds malicious payloads within bitmap resources of otherwise benign 32-bit .NET applications using steganography and layered loaders to deliver info-stealers and RATs (Agent Tesla, XLoader, Remcos); the report reconstructs the unpacking chain, provides SHA-256 hashes, C2 domains and SMTP exfiltration credentials, and recommends detection/mitigation approaches such as intercepting ResourceManager and Assembly.Load calls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
