A reported intrusion chain tied to APT28 combines Office lures, COM hijacking, PNG steganography, and reflective loading to keep payloads out of sight and traffic inside trusted services.
A reported intrusion chain combines COM hijacking, image-based concealment, and AES encryption, showing how ordinary Windows features can be bent into a stealth delivery path.