Crypto Ticker:
sysadmin from Cyber Security News

APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor

Tushar Subhra Dutta
Jul 8, 2026 at 22:13
30 Views
0 Comments
APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor

A well known hacking group has found a clever way to sneak malicious code past security tools, using an ordinary picture file. The group, tracked as APT-C-20 and known as APT28 or Fancy Bear, hides shellcode inside PNG images to launch a fileless backdoor written in C#. This lets attackers avoid dropping malware files on disk, making the intrusion harder to spot. The campaign begins with a booby trapped Word document sent as an email attachment, disguised as a defense related file tied to an Eastern European government. Once a victim enables macros, the document drops a hidden DLL and a disguised PNG image, then hijacks a Windows component to load code without raising alarms. The DLL pulls hidden shellcode from the image and...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!