During an incident response investigation in the final quarter of 2017, BlackBerry Cylance incident responders and threat researchers uncovered several bespoke backdoors deployed by the OceanLotus APT Group. The complexity of the shellcode and loaders shows the group continues to invest heavily in development of bespoke tooling. The payload loader that utilizes steganography to read an encrypted payload concealed within a.png image file can be easily modified by the threat actor to deliver other malicious payloads. This new white paper describes the Steganography algorithm used in two distinct loader variants.”]
Source: https://blogs.blackberry.com/en/2019/04/report-oceanlotus-apt-group-leveraging-steganography

