typeconceptconfidencemediumcreated2026-08-11updated2026-08-19dotnetobfuscationloaderbitmap-steganographypayload-deliverysteganographyunclassified

Bitmap Steganography Payload Delivery

Cross-family concept for malware that hides executable payloads inside seemingly benign image resources embedded in the PE file. The outer binary appears to be a normal .NET application with embedded bitmaps; the actual malicious code is encrypted and scattered across the pixel data of those images.

Pattern Definition

  1. Embed carrier images — 4–300 small bitmaps (typically 76×76×24 BMP or 256×256 PNG) are added as .rsrc or .text embedded resources in a .NET Framework PE32 executable.
  2. Pixel extraction — At runtime, the loader iterates ResourceManager.GetObject() or Bitmap.LockBits() to read raw pixel byte arrays from each image.
  3. Reconstruct ciphertext — Pixel bytes are concatenated or channel-split (R/G/B/A) to form an encrypted payload buffer.
  4. Symmetric decryption — RijndaelManaged / AesManaged + CryptoStream over MemoryStream decrypts the buffer. No hardcoded key is visible statically; the key is either derived from image metadata (dimensions, palette) or embedded in a separate resource.
  5. Reflective loading — Assembly.Load(decryptedBytes) → Type.GetType() / GetMethod() → Invoke() executes the inner payload without ever writing to disk.

Variants Observed

Variant Bitmap Count Dimensions Section Format Notes
4bf14434 ~20 76×76×24 .rsrc BMP Baseline cluster member
f31920ba 4 mixed 256×256 PNG + 129×128 BMP + 513×513 PNG .text PNG+BMP Fewer, larger carriers; bank GUI masquerade
9ac1c1db 283 76×76×24 .text BMP Extreme carrier count; clinical-trial lure
966baf32 22 76×76×24 .rsrc BMP Spanish purchase-order lure; Apr 2026 build
0becdb662b 2 BMP 180×180×32 + PNG 650×698 RGBA .text BMP+PNG "FlashQuiz" Uzbek quiz GUI masquerade; no cipher strings recovered

Detection

  • Static: binwalk / pefile resource enumeration shows repeated PC bitmap or PNG image structures. strings shows System.Drawing.Bitmap and System.Resources.ResourceReader references.
  • Dynamic: ETW .NET module-load events show System.Drawing.dll + System.Security.Cryptography.dll loaded within seconds of process start, followed by Assembly.Load events with no corresponding disk file.
  • Memory: Search process heaps for BMP file headers (BM) or PNG signatures (\x89PNG) after resource extraction but before decryption.

Related