216.73.217.98

Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources

· Published 09/05/2025 20:58 · Modified 12/05/2025 08:46

Export JSON

Essential information

Published
09/05/2025 20:58
Modified
12/05/2025 08:46
Tags
.net 2025-05-09 agent-tesla bitmap malspam multi-stage obfuscation remcos rat steganography xloader
Related entities
10 techniques (mitre), 3 malware, 2 others

Description

This article discusses a new technique used by threat actors to conceal malware within resources embedded in seemingly benign 32-bit .NET applications. The malware employs a process to extract, deobfuscate, load, and execute secondary payloads, ultimately leading to the detonation of the final payload. The analysis focuses on malware samples from recent campaigns targeting financial organizations in Turkey and the logistics sector in Asia. The article provides a detailed technical breakdown of the four stages involved in the malware's execution, from the initial payload to the final Agent Tesla variant. It also offers insights into effective analysis approaches and protection measures against this -based threat.

External references