Suspicious PowerShell .NET Extraction from JPG with Base64 Marker

PremiumReviewedSigma · High · v1
Product
windows
Category
ps_script
Author
HuntRule
Published
2026-09-22
Updated
2026-09-22

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects PowerShell reading a jpg image and carving an embedded payload delimited by a base64 start marker. Ande Loader hid an AES encrypted .NET assembly inside a new image jpg between BASE64_START markers before hollowing AddInProcess32. Extracting executable code from an image file this way is a steganography style loader technique.

Related detections6 linkedT1027.003 — drag to rearrange
Malicious LSB Steganography Image Decoding via PowerShell (via ps_script)
Linux steghide steganography: Extract hidden files from JPG/PNG
Linux auditd: Steghide embeds hidden files via steghide embed with -cf/-ef
Linux auditd: cat appends ZIP data to image files
Linux auditd: Unzip files extracted from JPG/PNG images
Windows findstr Launches .lnk via Command Line
Suspicious PowerShell .NET Extraction from JPG with Base64 Marker
Pivot detection · T1027.003 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.