A reported intrusion chain tied to APT28 combines Office lures, COM hijacking, PNG steganography, and reflective loading to keep payloads out of sight and traffic inside trusted services.