A well known hacking group has found a clever way to sneak malicious code past security tools, using an ordinary picture file. The group, tracked as APT-C-20 and known as APT28 or Fancy Bear, hides shellcode inside PNG images to launch a fileless backdoor written in C#. This lets attackers avoid dropping malware files on disk, making the intrusion harder to spot. The campaign begins with a booby trapped Word document sent as an email attachment, disguised as a defense related file tied to an Eastern European government. Once a victim enables macros, the document drops a hidden DLL and a disguised PNG image, then hijacks a Windows component to load code without raising alarms. The DLL pulls hidden shellcode from the image and...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!