PixyNetLoader is a Windows DLL-based malware loader associated with APT28 espionage operations. It has been used in campaigns targeting government, military, public-sector, maritime, transport, and other organizations in Central and Eastern Europe, particularly Ukraine, Slovakia, and Romania. The loader is notably linked to exploitation of Microsoft Office vulnerability CVE-2026-21509 through weaponized Office documents and localized lure content.
After initial compromise, PixyNetLoader is installed by an earlier-stage dropper and establishes persistence on the host, most notably through COM hijacking; some observed chains also used a temporary scheduled task to restart Explorer and trigger malicious DLL loading. The loader drops supporting components, including a companion PNG image and a malicious DLL that proxies legitimate functionality to reduce suspicion. A defining feature of PixyNetLoader is its use of PNG steganography: it extracts hidden shellcode or a staged payload from the least significant bits of image pixels and executes the recovered code in memory. Observed variants ultimately deploy a Covenant Grunt implant, providing the operators with post-compromise command-and-control capability.
Later PixyNetLoader variants show increased sophistication in payload protection and evasion. Reported evolutions include shared string-encryption routines across families, in-memory execution, DLL proxying, anti-analysis timing checks, and more advanced cryptographic processing around the hidden payload. Family C variants introduced a stronger extraction and decryption workflow using an embedded secret, key derivation, and AES-based decryption before executing the final implant. Some variants also embedded the PNG resource directly in the binary.
PixyNetLoader has been observed across multiple code families from 2024 through 2026, indicating sustained development and operational reuse. Its role is not broad data theft by itself, but reliable staging, persistence, stealthy payload delivery, and execution of follow-on implants. In documented operations, the final payload has consistently been Covenant Grunt using the FILEN cloud service for command-and-control, reflecting APT28's preference for blending malicious traffic with legitimate cloud services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Spoločnosť Microsoft vydala mimoriadne bezpečnostné aktualizácie kancelárskeho balíka Microsoft Office, ktoré opravujú aktívne zneužívanú zero-day zraniteľnosť. CVE-2026-21509 možno zneužiť podvrhnutím špeciálne vytvorených súborov na obídenie bezpečnostných mechanizmov pre ochranu pred zneužitím niektorých funkcií COM/OLE a získanie úplnej kontroly nad systémom. | Cieľom je nainštalovať malvér MiniDoor (kradne e-maily) a PixyNetLoader, ktorý nainštaluje útočný nástroj Covenant.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cieľom je nainštalovať malvér MiniDoor (kradne e-maily) a PixyNetLoader, ktorý nainštaluje útočný nástroj Covenant.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Executes the following command using the CreateProcess Windows API to set up a Windows scheduled task... schtasks.exe /Create /tn "OneDriveHealth" /XML "%temp%\Diagnostics\office.xml"
Cieľom je nainštalovať malvér MiniDoor (kradne e-maily) a PixyNetLoader, ktorý nainštaluje útočný nástroj Covenant.
“%windir%\system32\cmd.exe /c (taskkill … explorer.exe) & (start explorer …) & (schtasks /delete …)”
This threat fits a relatively standard compromise scheme through vulnerability exploitation via a malicious .DOC file ( CVE-2026-21509 in February 2026) executing a version of the SimpleDropper code
Uses COM object hijacking to establish persistence. EhStorShell.dll is the legitimate name for the Enhanced Storage Shell Extension DLL. By setting the Windows registry keys listed in the table below, PixyNetLoader ensures that the next-stage malicious shellcode loader DLL is loaded each time the explorer.exe process starts.
Executes the following command using the CreateProcess Windows API to set up a Windows scheduled task... schtasks.exe /Create /tn "OneDriveHealth" /XML "%temp%\Diagnostics\office.xml"
APT28 evolved PixyNetLoader, utilizing COM persistence, PNG steganography, and FILEN-based cloud C2
All the embedded payloads are decrypted and dropped to the file system locations in the table below: %programdata%\Microsoft OneDrive\setup\Cache\SplashScreen.png ... %temp%\Diagnostics\office.xml
The embedded and hashed secret is then transformed into an AES key via a PBKDF2 HMAC SHA256 of 20000 iterations using the extracted SALT The header is decrypted
CVE-2026-21509 možno zneužiť podvrhnutím špeciálne vytvorených súborov na obídenie bezpečnostných mechanizmov pre ochranu pred zneužitím niektorých funkcií COM/OLE a získanie úplnej kontroly nad systémom.
“Creates a mutex with the static name adjgfenkbe.” / “Creates a mutex with the name asagdugughi41.” / “Creates a mutex named dvyubgbqfusdv32.”
the loader only activates its malicious logic if the infected machine is not an analysis environment and when the host process that launched the DLL is "explorer.exe." The malware stays dormant if the conditions are not met.
Uses COM object hijacking to establish persistence. EhStorShell.dll is the legitimate name for the Enhanced Storage Shell Extension DLL. By setting the Windows registry keys listed in the table below, PixyNetLoader ensures that the next-stage malicious shellcode loader DLL is loaded each time the explorer.exe process starts.
The Grunt payload uses the FILEN cloud service as its command-and-control channel.
CERT-UA said. "During the investigation, it was found that opening the document using Microsoft Office leads to establishing a network connection to an external resource using the WebDAV protocol..."
123 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used by APT28 featuring COM persistence, PNG steganography, and cloud-based C2 via FILEN.
A DLL-based malware loader that uses steganography to hide encrypted payloads inside PNG image files, installs persistence via COM, extracts a Covenant Grunt payload from image pixel LSBs, and executes it in memory while using the FILEN cloud service for command-and-control.
A malware loader attributed to APT28 that exploits a Microsoft Office vulnerability to deliver a COVENANT Grunt implant.
A DLL-based loader used by APT28 that is typically dropped after document-based exploitation, installed via COM persistence, and loads a companion PNG file to extract and decrypt an embedded payload via steganography. Newer Family C variants derive AES keys from an embedded secret and execute the decrypted payload in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.