APT-C-20 Uses Steganography to Deploy Fileless C# Backdoor
Article Content
- •APT-C-20 uses LSB steganography to hide malicious code in PNG images.
- •The attack employs a fileless C# backdoor that avoids traditional malware detection.
- •Organizations using vulnerable Office documents and cloud services are at risk.
APT-C-20, also known as Fancy Bear or APT28, has launched a new intrusion campaign utilizing advanced techniques to evade detection. The group employs LSB steganography to hide shellcode within PNG images, allowing them to execute a fileless C# remote-control Trojan. This method leverages weaponized Office documents that deploy a COM-hijacking DLL to facilitate the attack. The backdoor communicates through legitimate cloud storage services, enhancing its stealth. The campaign reflects the group's ongoing evolution in cyber tactics, focusing on stealth and evasion. Organizations using vulnerable Office applications and cloud storage services are at risk. The full scope of the impact is still being assessed as the campaign is ongoing.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track APT28 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
2026 AV-Comparatives EPR Test Results Released AV-Comparatives published the results of its 2026 Endpoint Prevention and Response (EPR) Test, evaluating 14 enterprise security products against 50 multi-stage attack scenarios. The test, which ran from May to August 2026, incorporated AI-assisted techniques and followed the MITRE ATT&CK framework. Eleven products…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…