Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026
Key takeaways
- Analysis of ~90 PixyNetLoader samples and grouping them into 4 sub-families using code similarities sharing
- Enabling unified detection through a single YARA rule
- Exposing the latest steganography mechanisms used in the 2026 March-April versions
- Provinding PNG payload extraction script, IOCs, detection guidance and samples list
In this article, we will examine the evolutions of the APT28 PixyNetLoader code family, and how, by analyzing approximately 90 samples and studying the shared code between them, we can identify 4 major different sub-families that we will briefly detail, and produce a single YARA rule to match all of these codes.
Read more...