Steganography

T1027.003

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide data in digital media such as images, audio tracks, video clips, or text files.

Duqu was an early example of malware that used steganography. It encrypted the gathered information from a victim's system and hid it within an image before exfiltrating the image to a C2 server.

By the end of 2017, a threat group used Invoke-PSImage to hide PowerShell commands in an image file (.png) and execute the code on a victim's system. In this particular case the PowerShell code downloaded another obfuscated script to gather intelligence from the victim's machine and communicate it back to the adversary.

Detection rules5

Rules on DetectionCode tagged with T1027.003.

Sigma5

Splunk0

No Splunk rules are mapped to this technique yet.

Groups10

Software19

Campaigns2

Procedure examples31

Groups10

Used byProcedure example
GroupAndariel

Andariel has hidden malicious executables within PNG files.

GroupAPT-C-36

APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.

GroupAPT37

APT37 uses steganography to send images to users that are embedded with shellcode.

GroupBRONZE BUTLER

BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads.

GroupEarth Lusca

Earth Lusca has used steganography to hide shellcode in a BMP image file.

GroupLeviathan

Leviathan has used steganography to hide stolen data inside other files stored on Github.

GroupMuddyWater

MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg.

GroupTA551

TA551 has hidden encoded data for malware DLLs in a PNG.

View all 10 groups examples

Software19

Used byProcedure example
MalwareABK

ABK can extract a malicious Portable Executable (PE) from a photo.

MalwareAvenger

Avenger can extract backdoor malware from downloaded images.

MalwareBandook

Bandook has used .PNG images within a zip file to build the executable.

MalwareBBK

BBK can extract a malicious Portable Executable (PE) from a photo.

Malwarebuild_downer

build_downer can extract malware from a downloaded JPEG.

MalwareDiavol

Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques.

MalwareIcedID

IcedID has embedded binaries within RC4 encrypted .png files.

ToolInvoke-PSImage

Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file.

View all 19 software examples

Campaigns2

Used byProcedure example
CampaignOperation Ghost

During Operation Ghost, APT29 used steganography to hide payloads inside valid images.

CampaignOperation Spalax

For Operation Spalax, the threat actors used packers that read pixel data from images contained in PE files' resource sections and build the next layer of execution from the data.

References2

  1. McAfee Malicious Doc Targets Pyeongchang Olympics Open source
    Saavedra-Morales, J., Sherstobitoff, R. (2018, January 6). Malicious Document Targets Pyeongchang Olympics. Retrieved April 10, 2018.
  2. Wikipedia Duqu Open source
    Wikipedia. (2017, December 29). Duqu. Retrieved April 10, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.