logo

TA558 Hackers Weaponize Images for Wide-Scale Malware Attacks

ID: bb115ae6-5a4d-5c70-88c9-e3cec649716b

STIX ID: report--bb115ae6-5a4d-5c70-88c9-e3cec649716b

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-16

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

TA558 (campaign codename SteganoAmor) is leveraging steganography—embedding obfuscated VBS, PowerShell, and exploit-laden documents inside images and text files—to deliver a range of malware (Agent Tesla, FormBook, Remcos RAT, LokiBot, GuLoader, Snake Keylogger, XWorm) via phishing emails that exploit CVE-2017-11882; attacks have targeted industrial, services, electric power and construction sectors across Latin America and other countries, using compromised SMTP/FTP and paste/image hosting for payload staging and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.