Bitmap Steganography Payload Delivery
Cross-family concept for malware that hides executable payloads inside seemingly benign image resources embedded in the PE file. The outer binary appears to be a normal .NET application with embedded bitmaps; the actual malicious code is encrypted and scattered across the pixel data of those images.
Pattern Definition
- Embed carrier images — 4–300 small bitmaps (typically 76×76×24 BMP or 256×256 PNG) are added as
.rsrcor.textembedded resources in a .NET Framework PE32 executable. - Pixel extraction — At runtime, the loader iterates
ResourceManager.GetObject()orBitmap.LockBits()to read raw pixel byte arrays from each image. - Reconstruct ciphertext — Pixel bytes are concatenated or channel-split (R/G/B/A) to form an encrypted payload buffer.
- Symmetric decryption —
RijndaelManaged/AesManaged+CryptoStreamoverMemoryStreamdecrypts the buffer. No hardcoded key is visible statically; the key is either derived from image metadata (dimensions, palette) or embedded in a separate resource. - Reflective loading —
Assembly.Load(decryptedBytes)→Type.GetType()/GetMethod()→Invoke()executes the inner payload without ever writing to disk.
Variants Observed
| Variant | Bitmap Count | Dimensions | Section | Format | Notes |
|---|---|---|---|---|---|
| 4bf14434 | ~20 | 76×76×24 | .rsrc |
BMP | Baseline cluster member |
| f31920ba | 4 mixed | 256×256 PNG + 129×128 BMP + 513×513 PNG | .text |
PNG+BMP | Fewer, larger carriers; bank GUI masquerade |
| 9ac1c1db | 283 | 76×76×24 | .text |
BMP | Extreme carrier count; clinical-trial lure |
| 966baf32 | 22 | 76×76×24 | .rsrc |
BMP | Spanish purchase-order lure; Apr 2026 build |
| 0becdb662b | 2 | BMP 180×180×32 + PNG 650×698 RGBA | .text |
BMP+PNG | "FlashQuiz" Uzbek quiz GUI masquerade; no cipher strings recovered |
Detection
- Static: binwalk /
pefileresource enumeration shows repeatedPC bitmaporPNG imagestructures.stringsshowsSystem.Drawing.BitmapandSystem.Resources.ResourceReaderreferences. - Dynamic: ETW
.NETmodule-load events showSystem.Drawing.dll+System.Security.Cryptography.dllloaded within seconds of process start, followed byAssembly.Loadevents with no corresponding disk file. - Memory: Search process heaps for BMP file headers (
BM) or PNG signatures (\x89PNG) after resource extraction but before decryption.
Related
- unclassified-dotnet-bitmap-stego-loader — Primary cluster in this corpus
- aes-managed-overlay-decryption — Related .NET decryption pattern using raw overlay instead of bitmaps
- dotnet-manifest-resource-decryption — Related pattern using manifest resources instead of bitmaps
- reflective-assembly-delegate-execution — Final execution stage shared across these families