Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OilRig Hides C2 Data in Images on Google Drive with Steganography

OilRig Hides C2 Data in Images on Google Drive with Steganography

Posted on April 28, 2026 By CWS

An Iranian state-sponsored hacking group known as OilRig, also identified as APT34 and Helix Kitten, has recently been discovered utilizing images stored on Google Drive to conceal its command-and-control (C2) server configurations. This sophisticated method employs LSB (Least Significant Bit) steganography to embed encrypted data within a PNG file, making detection by standard security tools exceptionally challenging.

Background on OilRig’s Cyber Activities

OilRig, active since 2016, is widely believed to be linked to Iranian intelligence. This cyberespionage group has a history of targeting various organizations across the Middle East, the United States, Europe, and parts of Asia. Their primary focus includes government bodies, financial institutions, energy companies, telecom firms, and chemical enterprises. The main objective of these attacks is to exfiltrate sensitive political, military, and geostrategic information from high-value entities.

Unveiling the Steganographic Technique

Researchers at the 360 Advanced Threat Research Institute uncovered multiple attack samples attributed to OilRig during their routine threat hunting operations. This investigation revealed a sophisticated attack chain integrating phishing tactics, cloud service exploitation, and image steganography to execute a multi-stage espionage campaign. OilRig crafted phishing documents themed around Iran’s social protests to lure victims into inadvertently initiating the infection process.

The attack commenced with a malicious Excel file, titled “Final List_Tehran.xlsm,” designed to appear legitimate and linked to real-world events. It referenced January 1404 in the Iranian calendar, aligning with December 2025 to January 2026, enhancing its credibility. Once victims enabled macros within this document, the infection chain activated stealthily.

Advanced Attack Chain Analysis

OilRig’s attack strategy seamlessly integrated platforms such as GitHub, Google Drive, and Telegram for payload delivery and ongoing command execution. By leveraging widely trusted platforms, they significantly reduced the likelihood of their activities being flagged as suspicious by security systems.

The infection mechanism carefully avoided triggering security alerts at each phase. Upon macro activation, embedded VBA code decoded C# source code within the document’s CustomXMLParts section. Utilizing the Windows compiler csc.exe, it built a malicious loader, AppVStreamingUX_Multi_User.dll, on the victim’s system.

This loader connected to a GitHub repository, downloading a text file “tamiManager.txt,” which, after Base64 decoding, revealed a Google Drive link to an image named “MIO9.png.” Despite appearing normal, this image concealed encrypted C2 configuration data within its least significant bits.

Employing a custom LSB extraction algorithm along with Base64 and XOR decryption, the loader extracted the C2 setup, including a Telegram Bot token, a chat ID, and five module download addresses. These modules facilitated persistence, file manipulation, command execution, and application launch, operating entirely in memory to avoid leaving detectable footprints.

Recommendations for Enhancing Security

To mitigate such threats, security teams should disable macro execution in Office files from untrusted sources and establish network monitoring rules to detect unusual outbound traffic to GitHub or Google Drive. Organizations are also advised to deploy endpoint detection solutions capable of identifying in-memory DLL loading, DLL side-loading, and process injection activities. These measures are crucial to counteract the sophisticated techniques employed in this campaign.

Stay informed by following us on Google News, LinkedIn, and X for more up-to-the-minute cybersecurity updates. Set CSN as a preferred source in Google for continuous insights.

Cyber Security News Tags:APT34, command-and-control, cyberespionage, Cybersecurity, Google Drive, Iranian hackers, LSB, OilRig, Phishing, Steganography

Post navigation

Previous Post: Medtronic Confirms Breach Amid ShinyHunters Threat
Next Post: Windows Shell Vulnerability Exploited, Microsoft Confirms

Related Posts

Historic Great Firewall Breach – 500GB+ Censorship Data Exposed Historic Great Firewall Breach – 500GB+ Censorship Data Exposed Cyber Security News
Swedish Power Grid Operator Confirms Data Breach Following Everest Ransomware Gang Claim Swedish Power Grid Operator Confirms Data Breach Following Everest Ransomware Gang Claim Cyber Security News
Predator Spyware Compamy Used 15 Zero-Days Since 2021 to Target iOS Users Predator Spyware Compamy Used 15 Zero-Days Since 2021 to Target iOS Users Cyber Security News
Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable Cyber Security News
17,000+ VMware ESXi Servers Vulnerable to Critical Integer-Overflow Vulnerability 17,000+ VMware ESXi Servers Vulnerable to Critical Integer-Overflow Vulnerability Cyber Security News
Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices
  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices
  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark