IOC Radar
TLP:WHITE2 IOCs

Explorer COM Hijacking Attack Loads Shellcode From AES-Encrypted Steganographic PNG

CP
Cyber Press
Published July 8, 2026Original Report

Threat Actors

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYAPT28INFRASTRUCTUREunknownCAPABILITYunknownVICTIMunknown
Adversary(1)
Infrastructure
Capability
Victim

Attack Flow7 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1204.002
1/7
User Execution: Malicious Macro
ActionExecute malicious macro document
Victim opens a macro-enabled document (readme.docm) which displays scrambled text, tricking the user into enabling active content.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise2

TypeIndicatorConfidenceScoreFirst Seen
MD577014b3e77529079f041b5b9e73a013b
file-hashintel-blogloader
Medium
53
Jul 8, 26
MD5b077401fe3d9642345d4c3deafa60aa5
file-hashintel-blogloader
High
85
Jun 5, 26

IOC Relationship Graph

IOC Relationship Graph2 total IOCs
MD5
MD52Actors1REPORTExplorer COM Hijacking AttAPT28
scroll to zoom · drag to pan · click IOC to open