OilRig Uses LSB Steganography to Conceal C2 Configurations in Google Drive Images
Article Content
- •OilRig employs LSB steganography to hide C2 configurations in Google Drive images.
- •The group targets critical sectors including government and energy, posing a broad risk.
- •This attack showcases the evolving tactics of state-sponsored cyber threat actors.
The Iranian APT group OilRig, also known as APT34 and Helix Kitten, has launched a new attack campaign utilizing LSB (Least Significant Bit) steganography to hide command-and-control (C2) configurations within PNG images stored on Google Drive. This sophisticated method allows the group to embed encrypted data within seemingly innocuous image files, making detection challenging. OilRig primarily targets sectors such as government, energy, telecommunications, and finance, indicating a broad potential impact across critical infrastructures. The group has been active since at least 2014, and this recent tactic highlights their evolving strategies in cyber operations. There are no specific CVEs or tools mentioned in the articles, but the use of steganography represents a significant advancement in their operational security. As of now, the full scope of the impact remains unclear, but the stealthy nature of the attack raises concerns among cybersecurity professionals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Apt34 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…