216.73.216.6

A Multi-Stage Steganographic Loader Campaign Deploying Diverse Payloads Globally

· Published 23/06/2026 19:35

Export JSON

Essential information

Published
23/06/2026 19:35
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
agent tesla credential theft dark cloud fileless formbook infostealer loader-as-a-service masslogger phantom stealer phishing campaign process hollowing red line stealer remcos rat snake steganography xworm
Related entities
1 indicators, 18 techniques (mitre), 10 malware

Description

A sophisticated was identified distributing multiple malware families through a multi-stage loader utilizing and techniques. The infection chain begins with archive attachments containing files disguised as financial documents, primarily targeting Indian organizations using names related to GST, NEFT, RTGS, and IMPS transactions. The loader employs in-memory execution to avoid disk-based artifacts and uses embedded .NET Bitmap objects to conceal payloads. Various malware families have been deployed including , , , , Dark Cloud, Red Line Stealer, keyloggers, , and . The final payloads establish persistence through registry Run keys, perform , steal browser credentials, record audio and webcam, and exfiltrate data to command-and-control infrastructure. The campaign exhibits characteristics of a operation serving multiple threat actors globally.

External references