Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org
Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide data in digital media such as images, audio tracks, video clips, or text files.
Duqu was an early example of malware that used steganography. It encrypted the gathered information from a victim's system and hid it within an image before exfiltrating the image to a C2 server.
By the end of 2017, a threat group used Invoke-PSImage to hide PowerShell commands in an image file (.png) and execute the code on a victim's system. In this particular case the PowerShell code downloaded another obfuscated script to gather intelligence from the victim's machine and communicate it back to the adversary.
Rules on DetectionCode tagged with T1027.003.
| Rule | Level | Log source |
|---|---|---|
| Findstr Launching .lnk File | medium | windows / process_creation |
| Steganography Extract Files with Steghide | low | linux / NULL |
| Steganography Hide Files with Steghide | low | linux / NULL |
| Steganography Hide Zip Information in Picture File | low | linux / NULL |
| Steganography Unzip Hidden Information From Picture File | low | linux / NULL |
| Used by | Procedure example |
|---|---|
| GroupAndariel | Andariel has hidden malicious executables within PNG files. |
| GroupAPT-C-36 | APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files. |
| GroupAPT37 | APT37 uses steganography to send images to users that are embedded with shellcode. |
| GroupBRONZE BUTLER | BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads. |
| GroupEarth Lusca | Earth Lusca has used steganography to hide shellcode in a BMP image file. |
| GroupLeviathan | Leviathan has used steganography to hide stolen data inside other files stored on Github. |
| GroupMuddyWater | MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg. |
| GroupTA551 | TA551 has hidden encoded data for malware DLLs in a PNG. |
| Used by | Procedure example |
|---|---|
| MalwareABK | ABK can extract a malicious Portable Executable (PE) from a photo. |
| MalwareAvenger | Avenger can extract backdoor malware from downloaded images. |
| MalwareBandook | Bandook has used .PNG images within a zip file to build the executable. |
| MalwareBBK | BBK can extract a malicious Portable Executable (PE) from a photo. |
| Malwarebuild_downer | build_downer can extract malware from a downloaded JPEG. |
| MalwareDiavol | Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques. |
| MalwareIcedID | IcedID has embedded binaries within RC4 encrypted .png files. |
| ToolInvoke-PSImage | Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Ghost | During Operation Ghost, APT29 used steganography to hide payloads inside valid images. |
| CampaignOperation Spalax | For Operation Spalax, the threat actors used packers that read pixel data from images contained in PE files' resource sections and build the next layer of execution from the data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.