pip0

@pipzero.bsky.social

Information security practitioner. All things cti collection.

APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor

APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor

A well known hacking group has found a clever way to sneak malicious code past security tools, using an ordinary picture file. The group, tracked as APT-C-20 and known as APT28 or Fancy Bear, hides shellcode inside PNG images to launch a fileless backdoor written in C#. This lets attackers avoid dropping malware files on disk, making the intrusion harder to spot. The campaign begins with a booby trapped Word document sent as an email attachment, disguised as a defense related file tied to an Eastern European government. Once a victim enables macros, the document drops a hidden DLL and a disguised PNG image, then hijacks a Windows component to load code without raising alarms. The DLL pulls hidden shellcode from the image and runs it in memory, eventually deploying a remote access tool that talks to attackers through a cloud storage service. Analysts from 360 said in a report shared with Cyber Security News (CSN) that they identified the campaign while tracking APT-C-20 activity, noting the group’s tradecraft closely matches its historical operations. Their research shows the attackers combine several layers of deception, including macro encryption, hidden registry changes, and image based steganography, keeping the infection invisible for as long as possible. The impact is significant since the campaign targets government and diplomatic entities with convincing lures, and its fileless nature means antivirus tools often miss it. Since the final payload never touches disk as a standalone executable, defenders must rely on behavior based detection rather than file scanning. Organizations handling sensitive geopolitical data face heightened risk given the group’s history of espionage. APT-C-20 Hackers Hide Shellcode in PNG Images The attack starts with a document named readme.docm, a tiny file barely 469 bytes in size that shows garbled text until macros are enabled. Enabling macros reveals a decoy page about an Eastern European defense ministry, distracting the user while hidden code runs in the background. The macro is encrypted, and once unlocked it checks the environment, drops files, sets up persistence, and gathers system information before showing fake content. The malware contacts dropbox.com as a network check , then copies itself into a temp folder and writes two files to a ProgramData location, a DLL named dnxstore.dll and an image called EdgeLogo.png. Attack Chain (Source – 360) A registry key tied to a built in Windows COM class is redirected to the malicious DLL. When Windows Explorer initializes that COM object, it unknowingly loads the attacker’s code, a technique known as COM hijacking. Once loaded, dnxstore.dll checks whether it runs inside explorer.exe rather than a debugging tool, and measures time delays to detect a sandbox. If everything looks legitimate, it opens EdgeLogo.png, which appears to be a normal Edge icon but hides encrypted data using least significant bit steganography. The malware derives an encryption key, pulls hidden salt and initialization vector values from the pixels, and decrypts a small header describing where the real payload sits. The Fileless C# Backdoor Payload After extracting the metadata, the loader pulls the encrypted shellcode from the image pixels, decrypts it, and runs it entirely in memory without saving it as a file. This shellcode reflectively loads the final payload, a C# backdoor called Publish.exe, heavily obfuscated to resist analysis. Once active, the backdoor builds a unique identifier from the victim’s username and domain name, then packages system details into a JSON message that gets encrypted and sent out. Instead of a typical command and control server, it communicates through Filen.io, a cloud storage service, using multiple backup gateways so it keeps working if one node fails. It waits for instructions, exchanges encryption keys with the operator, and loads additional code sent to it. Researchers noted this reflective loading style and cloud based communication matches previous APT-C-20 activity documented in earlier reports. The security teams should treat unexpected macro enabled documents with caution and avoid opening attachments or links from unfamiliar senders. Monitoring unusual explorer.exe behavior and traffic to cloud APIs can help catch this intrusion early. Indicators of compromise (IoCs):- Type Indicator Description File readme.docm Malicious macro enabled Word document used as initial lure, 469 bytes  File dnxstore.dll Shellcode loader DLL dropped via COM hijacking  File EdgeLogo.png PNG image containing LSB steganography-hidden shellcode  File Publish.exe Final C# backdoor payload communicating via Filen.io  Domain dropbox.com Contacted during initial network reconnaissance check  Domain gateway.filen.io C2 gateway node for Filen.io based communication  Domain gateway.filen.net Backup C2 gateway node for Filen.io based communication  MD5 77014b3e77529079f041b5b9e73a013b Hash of readme.docm lure document  MD5 b077401fe3d9642345d4c3deafa60aa5 Hash of dnxstore.dll loader  MD5 1cbffddcb8e1e839737bbf6e50a80aaf Hash associated with attack component  MD5 f10d1676b570aa4d97edb844fbb5128 Hash associated with attack component  MD5 7c517d1f4385e0d6e8fa5932d17873eb Hash associated with attack component  MD5 8d416eca59188474efa3408827578588b Hash of Publish.exe C# backdoor payload  Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Prevent critical incidents and financial loss with stronger proactive defense.  Integrate a live threat feed from 15K SOC Teams . The post APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor appeared first on Cyber Security News .

cybersecuritynews.com

Hackers Breached Klue Integration to Steal Salesforce CRM Data via OAuth Tokens

Hackers Breached Klue Integration to Steal Salesforce CRM Data via OAuth Tokens

Threat actors exploited a trusted third-party SaaS integration to silently harvest enterprise CRM data, marking the latest chapter in an escalating wave of OAuth-abuse attacks targeting Salesforce ecosystems. Researchers at ReliaQuest observed attackers leveraging a compromised Klue Battlecards integration, a competitive-intelligence platform that synchronizes battlecard and win/loss data with Salesforce, to exfiltrate large volumes of customer relationship management (CRM) data from enterprise environments. In response, Salesforce has officially disabled the Klue Battlecards app’s connection to its platform pending further investigation, warning that the unusual activity “may have resulted in unauthorized access to a subset of customer data.” Salesforce confirmed the issue is not a vulnerability within its own platform, but rather a compromise of Klue’s integration service account credentials. The attackers authenticated through compromised Klue integration service accounts, generated OAuth tokens, and deployed automated Python scripts identifiable by Python-urllib user-agent strings to systematically drain CRM records via Salesforce’s REST API. The attack followed a two-phase exfiltration pattern: Phase 1 – Slow extraction: Attackers first enumerated the organization’s object catalog via GET /services/data/v59.0/sobjects , then ran sustained looped REST API queries over nearly 24 hours, paginating results through the QueryMore cursor in a pattern designed to mimic legitimate integration traffic. Phase 2 – Burst extraction: In at least one environment, attackers sent nearly 1,000 queries within a 15-minute window, trading stealth for speed — suggesting either time pressure or a targeted pivot to high-value records. A separate incident saw sustained extraction lasting over 6 hours. The CRM data accessible through the integration could include account records, contact details, deal outcomes, and pricing data, depending on how each organization scoped the integration’s permissions. ReliaQuest researchers noted the attack methodology closely mirrors campaigns attributed to ShinyHunters and UNC6395, two threat clusters responsible for high-profile Salesforce OAuth-abuse incidents throughout 2025 and 2026. In June 2025, ShinyHunters used voice phishing to trick employees into authorizing malicious connected apps, then bulk-extracted Salesforce data for extortion. In August 2025, UNC6395 stole OAuth refresh tokens from the Salesloft Drift integration and queried Salesforce data across hundreds of organizations — the closest public analog to this incident. However, attribution remains unconfirmed. Key differences exist: UNC6395 was previously used python-requests , Salesforce-CLI, and Tor infrastructure, while this activity used a generic Python-urllib agent and data-center hosting. No extortion demands or leak-site postings have been observed as of publication. The core vulnerability here is structural. Third-party SaaS integrations function as non-human identities with persistent, often broadly scoped API access to sensitive data. Because they authenticate with valid credentials, they rarely trigger the behavioral alerts associated with user account compromise, allowing a 24-hour automated query loop to run undetected from a “trusted” account. ReliaQuest’s GreyMatter platform correlated the OAuth token refresh, sustained API query spikes, and burst extraction activity into a single intrusion narrative, demonstrating why API-layer visibility is critical in integration-heavy environments. Organizations using Klue or any Salesforce-connected integration should act immediately: Revoke and rotate all credentials — including service-account passwords, OAuth refresh tokens, client secrets, and active OAuth grants. Revoking the refresh token, not just the password, is what terminates persistent access. Audit Salesforce REST API logs — hunt for unusual query volumes, repeated pagination, Python-urllib user-agents, and access from unknown IP ranges. Enforce IP allowlisting — restrict connected app and SIEM/SOAR API access to approved infrastructure only, blocking and alerting on all out-of-scope requests. ReliaQuest assesses it is highly likely that threat actors will continue targeting Salesforce-connected third-party integrations through the remainder of 2026, warning that the OAuth-abuse playbook is “repeatable, effective, and now widely adopted.” Artifact Type 138.226.246[.]94 IP Address 212.86.125[.]24 IP Address 213.111.148[.]90 IP Address 94.154.32[.]160 IP Address Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates. The post Hackers Breached Klue Integration to Steal Salesforce CRM Data via OAuth Tokens appeared first on Cyber Security News .

cybersecuritynews.com

This seems to be a prevalent issue now: People vibe code security applications and the LLM generates real malware for testing. The generated test files rely on real threat actor infrastructure to download or exfiltrate. hxxps://github.com/DataDog/guarddog/blob/main/tests

BildBild

You can now pull Ghidra databases straight into your workflow in Binary Ninja 5.2! Open a .gbf on its own, import Ghidra data into an existing session, or bring parts of a full project into a Binary Ninja project on Commercial and above.

Bild

🚨 The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions! Deep dive analysis in this obfuscated campaign including (PowerShell & VBS scripts, PE malware, Malicious browser extensions even stegomalware) Enjoy reading securitylabs.datadoghq.com/articles/mut...

The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions | Datadog Security Labs

Analysis of a threat actor campaign targeting Solidity developers via three malicious VS Code extensions

securitylabs.datadoghq.com

Green card holders detained. A French researcher denied entry for anti-Trump messages. A new travel ban on 40+ countries coming. Given all these encroachments on travelers' civil liberties, we've updated our guide to digital privacy while crossing US borders. www.wired.com/2017/02/guid...

How to Enter the US With Your Digital Privacy Intact

Crossing into the United States has become increasingly dangerous for digital privacy. Here are a few steps you can take to minimize the risk of Customs and Border Patrol accessing your data.

wired.com