Utilizing AI Models to Conceal and Extract Commands in C2 Images

Black Hat Asia 2025 · Day 2 · Briefings

Overview

This talk, "Utilizing AI Models to Conceal and Extract Commands in C2 Images," presented by Chen Fang and Chris Nawarte from Palo Alto Networks, delves into a sophisticated new frontier for command and control (C2) operations: deep image steganography powered by artificial intelligence. The researchers demonstrate how neural networks can be trained to conceal malicious payloads within seemingly innocuous images and extract them with high fidelity, effectively creating an AI-enhanced C2 framework. This research is critical for the security community, as it exposes a novel method attackers could use to bypass traditional detection mechanisms that rely on binary analysis, code analysis, or signature-based C2 traffic identification.

Watch on YouTube

Visual summary for Utilizing AI Models to Conceal and Extract Commands in C2 Images
Visual summary for Utilizing AI Models to Conceal and Extract Commands in C2 Images

Key moments

  1. 0:00 Introduction to AI-powered image steganography for C2
  2. 2:00 Overview of the AI steganography model architecture
  3. 3:20 Detailed steps for encoding malicious payload into images
  4. 4:00 Detailed steps for decoding secret commands from images
  5. 5:00 Loss functions and training tasks for the model
  6. 6:00 Evaluation: Specific data hiding is practical for attacks
  7. 6:40 Practicality: Payload size, training time, and model size
  8. 7:40 AI steganography bypasses signature-based C2 detection

Utilizing AI Models to Conceal and Extract Commands in C2 Images

Speakers: Chen Fang, Security Researcher, Palo Alto Networks; Chris Nawarte, Principal Security Researcher, Palo Alto Networks

Conference: Black Hat Asia

YouTube: https://www.youtube.com/watch?v=MoDYOm2fPJ0

Overview

This talk, "Utilizing AI Models to Conceal and Extract Commands in C2 Images," presented by Chen Fang and Chris Nawarte from Palo Alto Networks, delves into a sophisticated new frontier for command and control (C2) operations: deep image steganography powered by artificial intelligence. The researchers demonstrate how neural networks can be trained to conceal malicious payloads within seemingly innocuous images and extract them with high fidelity, effectively creating an AI-enhanced C2 framework. This research is critical for the security community, as it exposes a novel method attackers could use to bypass traditional detection mechanisms that rely on binary analysis, code analysis, or signature-based C2 traffic identification.

The core of their work focuses on the practical application of AI models for encoding and decoding arbitrary data, specifically malicious commands, within images. By showcasing a working prototype, the speakers illustrate how such a framework can achieve robust, stealthy communication between an attacker's server and compromised clients. This presentation serves as a vital wake-up call, emphasizing the need for defenders to understand these emerging AI-driven attack vectors to develop more resilient and adaptive defense strategies against increasingly advanced threats.

Background

▶ Watch: Introduction to AI-powered image steganography for C2 (0:00)

Steganography, the art and science of hiding information within other information, is not a new concept in cybersecurity. Traditionally, attackers have embedded payloads into various media formats, including images, using custom-designed encoder and decoder algorithms. These methods often require specific knowledge about the image's internal structure and pixel manipulation techniques, making the design of robust, undetectable steganography challenging. Detection of traditional steganography often relies on statistical analysis of image properties or identifying known steganographic algorithms.

However, the advent of deep image steganography introduces a paradigm shift. Instead of manually crafting algorithms, this approach leverages neural networks to automatically learn how to encode and decode data. The encoder and decoder themselves are AI models, trained to embed a secret message into a cover image to produce a stego image that appears visually identical to the cover image, yet subtly contains the hidden data. This machine learning-driven process eliminates the need for attackers to possess deep image processing knowledge, allowing the AI to learn optimal hiding mechanisms. Crucially, this method has the potential to bypass existing security solutions that primarily focus on binary analysis, code execution patterns, or signature-based detection, as the malicious content is never directly exposed in its raw form until after decoding. The problem thus becomes: how can defenders detect command and control traffic that is camouflaged by an AI model within common image files?

Key Findings

▶ Watch: Detailed steps for encoding malicious payload into images (3:20)

The researchers' primary discovery is the practical viability of using AI models for specific data hiding in C2 operations, demonstrating its superiority over generic data hiding for attack scenarios. Their key findings include:

  1. Specific Data Hiding is Practical and Highly Effective for C2: While training a generic model to hide arbitrary data proved largely unsuccessful (achieving a zero reconstruction success ratio even after 40 hours of training), training a model for specific data hiding—where the model is overfit to a small set of predefined payloads—yielded a 100% reconstruction success ratio within "a few seconds." This makes it highly practical for attackers who typically need to hide a limited set of commands.
  2. Efficient Training and Small Model Footprint: For a 100-bit malicious payload, the specific data hiding model could be trained in "less than 1 minute," resulting in a model size "smaller than six megabytes." These metrics confirm that the technique is feasible for real-world attacks, where rapid deployment and minimal overhead are crucial.
  3. Evasion of Signature-Based Detection: The research revealed that even when training the model twice with the same settings and payload, the resulting stego images exhibited "slightly different" diff images (the difference between the stego image and the original cover image). This variability in the embedding process means that the C2 images appear different each time, making it extremely difficult for signature-based detection systems to identify and block them. This inherent non-deterministic nature provides a significant advantage for attackers seeking stealth.
  4. Non-Linear Decoding Makes Reconstruction Difficult for Defenders: The decoder component of the AI model primarily consists of "a set of convolutional layer operations," which are inherently non-linear. This characteristic implies that even if a defender possesses both the cover image and the stego image, it is "hard for us to reconstruct those malicious payloads without a decoder." This highlights a significant challenge for forensic analysis and threat intelligence efforts.
  5. C2 Server-Side Training is Feasible: The requirement for specific data hiding, which involves training the model on a small, predefined set of payloads, is ideal for C2 scenarios. This training can be "conducted at the C2 server side," making it a reasonable and implementable step within an attacker's infrastructure.

These findings collectively underscore a significant evolution in C2 capabilities, demonstrating how AI can be leveraged to create highly evasive and robust communication channels.

Technical Deep Dive

▶ Watch: Loss functions and training tasks for the model (5:00)

The proposed AI Steg model for concealing and extracting commands within C2 images is built upon a neural network architecture comprising an encoder and a decoder. The overall architecture includes modules for converting secrets and images into tensors, and leverages reconstruction losses for both the secret and the image to guide the training process.

Data Conversion:

The initial step involves converting the raw data into a format suitable for neural network processing:

  1. Image to Tensor: Standard image processing steps are used. First, the image is loaded into a tensor format using a standard PyTorch library. Second, normalization is applied to these tensors.
  2. Malicious Payload (Secret) to Tensor: The malicious payload (e.g., a command string) is first converted into a bit array. This bit array is then loaded into a tensor format using PyTorch. The researchers also visualize these malicious tensors to confirm their structure.

Encoding Process:

The encoder takes the image tensor and the secret tensor as input and produces a stego image. The process involves several key steps:

  1. Secret Reshaping and Repetition: The secret tensor is reshaped and repeated to match the dimension of the original image tensor. This ensures that the secret can be effectively embedded across the image's feature space.
  2. Feature Learning on Image: The encoder performs "feature learning" on the original image tensor to extract higher-level feature vectors. This step helps the model understand the image's characteristics, allowing it to embed the secret without significantly altering the visual perception.
  3. Concatenation: The reshaped secret tensor, the higher-level feature vector of the image, and the original image tensor itself are concatenated. This combined tensor serves as the input for the subsequent encoding layers.
  4. Encoding Layers: Both the feature learning and encoding parts are implemented as a set of containers, each consisting of multiple layers. These layers typically include convolutional layers for feature extraction and pattern recognition, batch normalization layers for stabilizing and accelerating training, and a ReLU activation function to introduce non-linearity. The output of these layers is the stego image.

Decoding Process:

The decoder receives the stego image from the encoder and attempts to reconstruct the original secret message:

  1. Representation Learning: The decoder utilizes a set of containers (similar to the encoder, comprising convolutional and batch norm layers with ReLU activation) to learn the representation for the decoded message from the stego image.
  2. Pooling and Linear Conversion: After the convolutional layers, several average pooling operations are applied to reduce dimensionality and extract robust features. This is followed by a linear conversion to transform the learned features into a tensor that should ideally match the shape of the original secret tensor.
  3. Rounding Operation: A critical step is the rounding operation. The output of the decoded secret is initially a floating-point tensor. To convert this back into a meaningful bit array (0s and 1s), each entry in the tensor is rounded to either 0 or 1.
  4. Command Extraction: Finally, the rounded 0/1 tensor is considered a bit array, from which the original command can be extracted.

Loss Functions and Training:

To ensure the quality of both the stego image and the reconstructed secret, two loss functions are employed:

  1. Image Reconstruction Loss: The mean square error (MSE) is used to quantify how closely the stego image resembles the original cover image. The goal is to minimize this loss, making the stego image visually indistinguishable.
  2. Secret Reconstruction Loss: The L1 loss is used to quantify the accuracy of the reconstructed secret. Minimizing this loss ensures that the decoded secret is an exact match to the original payload.

Training Tasks and Evaluation:

The researchers explored two distinct training tasks:

  1. Generic Model Training: Aimed at hiding arbitrary data. This proved largely unsuccessful, with "zero reconstruction success ratio" even after "40 hours" of training.
  2. Specific Data Hiding Training: Focused on training the model on a small, specific set of payloads. This approach was highly successful, achieving a "100% reconstruction success ratio" within "a few seconds." This outcome is crucial for C2 scenarios where the attacker typically controls the commands to be hidden.

Further evaluation showed a direct correlation between payload size and both training time and model size. For instance, a 100-bit malicious payload could be encoded within "less than 1 minute" of training, resulting in a model size "smaller than six megabytes." This demonstrated the practical feasibility of specific data hiding for C2 attacks. The non-deterministic nature of the encoding, where different training runs with the same payload yield "slightly different" stego images, further enhances evasion capabilities by bypassing signature-based detection. The non-linear operations of the decoder also make it exceedingly difficult for defenders to reconstruct the hidden payload without access to the specific AI model.

Demo / Proof of Concept

▶ Watch: Evaluation: Specific data hiding is practical for attacks (6:00)

The core of the practical demonstration revolved around an AI-enhanced C2 framework prototype named imageC2. This framework showcases the entire lifecycle of an AI-powered image-based C2 operation, from model training to command execution and data exfiltration.

C2 Attack Flow:

The attack flow, as presented, involves a C2 client (the compromised machine) and a C2 server (attacker's infrastructure):

  1. Model Training: The C2 server first trains the AI model using specific data hiding techniques for the desired commands.
  2. Model and Image Hosting: The trained ML model and the generated stego images (each containing a specific command) are hosted on the C2 server.
  3. ML Model Retrieval (Client): The C2 client retrieves the pre-trained ML model.
  4. Requirements File Retrieval (Client): The client downloads a requirements.txt file, which specifies the necessary Python libraries for processing the ML model.
  5. Staging Key Retrieval (Client): The client retrieves a "staging key," which is an image file containing an encryption key embedded via steganography. This key is used for encrypting exfiltrated data.
  6. C2 Checking & Beaconing: The client establishes initial communication with the C2 server.
  7. New Task Search (Client): The C2 client periodically beacons to the server, looking for new commands.
  8. Image Retrieval (Client): Upon receiving a new task, the client retrieves a new stego image corresponding to the command.
  9. Command Extraction & Execution: The client uses the downloaded ML model to extract the concealed command from the image, executes it, and collects the output.
  10. Encrypted Exfiltration: The collected information is encrypted using the staging key and returned to the C2 server.

C2 Framework Components:

The imageC2 prototype consists of several components:

  • C2 Manager (API endpoint): Handles checking and beaconing from clients.
  • C2 Web Controller (PHP page): Manages infiltrated information, hosts supporting scripts (e.g., for decryption), the ML model, stego images, and the requirements.txt file.
  • Machine Learning Trainer: Responsible for crafting new stego images with embedded commands.
  • C2 Client (Python-based implant): The agent on the compromised machine.

Operational Commands:

The prototype supports five operational commands: my system info, list, ip config, and a payload execution command for a PowerShell reverse shell. Each command is mapped to a specific image file name (e.g., images for whoami or systeminfo).

Client-Side Processing:

The Python C2 client processes images by calling three functions: d_command, load_image, and get_cmd. These functions interact with the ML model and image tensor to extract the concealed content, which is typically a one-liner command like a PowerShell script.

Encryption and Exfiltration:

For secure communication, the client uses a dedicated class for encryption. It leverages the "staging key" (obtained from an earlier stego image) to encrypt collected information. The exfiltration occurs over HTTP using a dictionary structure, with data encoded in Base64 and encrypted using libraries like cryptography, hashlib, and AES-256 in GCM mode with a password-derived key. The HTTP request body contains cipher text, nonce, and tag.

Wireshark View and Live Demonstration:

The presentation included a Wireshark capture simulation, illustrating the distinct stages of communication:

  • Stage Zero: Downloading the ML model.
  • Stage One: Downloading requirements.txt.
  • Stage Two: Staging key retrieval (an image containing the encryption key).
  • Stage Three: C2 checking, followed by regular C2 beaconing.
  • New Task: When a new task is issued, an additional image (e.g., image.jpg for whoami) is retrieved.
  • Data Exfiltration: Encrypted command output is sent back to the server.

The live demonstration showcased the imageC2 tool in action. On the left side, the C2 client was run, while the attacker's machine (C2 server) was on the right.

  1. The imageC2 tool was initialized on the attacker's machine, listening for connections.
  2. The C2 client was executed, demonstrating the download of the ML model, requirements.txt, and the staging key.
  3. The client then performed C2 checking and beaconing.
  4. The attacker issued a whoami command. The client retrieved the corresponding image, extracted the command, executed it, encrypted the result, and exfiltrated it back to the server, which then displayed the whoami output.
  5. This process was repeated for systeminfo and ipconfig commands.
  6. Finally, a PowerShell reverse shell command was issued. The client executed the PowerShell one-liner, and a listener on the attacker's machine (port 8031) successfully received a reverse shell connection, allowing interaction with the compromised machine. The session was then gracefully exited.

This comprehensive demonstration effectively validated the practical implementation and operational capabilities of the AI-powered image-based C2 framework.

Defensive Implications

▶ Watch: AI steganography bypasses signature-based C2 detection (7:40)

The AI-enhanced C2 framework presented by Chen Fang and Chris Nawarte poses significant challenges for conventional cybersecurity defenses. The core issue lies in the use of deep image steganography, which fundamentally alters the characteristics of malicious communication.

  1. Evasion of Signature-Based Detection: The ability of the neural network to generate "slightly different" stego images for the same payload across different training runs means that attackers can bypass traditional signature-based detection mechanisms. These systems rely on identifying fixed patterns or hashes, which will be ineffective against dynamically generated stego images. Defenders need to move beyond static signatures for C2 image detection.
  1. Bypassing Binary and Code Analysis: Since the malicious commands are hidden within image pixels and extracted by a Python-based ML model, direct binary analysis or code analysis of network traffic or image files will likely fail to identify the embedded payload. The actual command only manifests after the client-side AI model decodes it, making it difficult to detect at the network or file-scanning layer.
  1. Challenges for Network Traffic Analysis: On the surface, the C2 traffic might appear as benign HTTP requests for image files. While an influx of image downloads might raise suspicion, distinguishing legitimate image traffic from steganographic C2 images is extremely difficult without the specific decoder. The exfiltrated data is also encrypted and Base64 encoded, further obscuring its malicious nature.
  1. Endpoint Detection and Response (EDR) Evasion: The C2 client is a Python-based implant that downloads an ML model and a requirements.txt file. While these activities might be suspicious, they are not inherently malicious. EDR systems would need to identify the specific behavioral chain: downloading an ML model, loading it with PyTorch (or similar libraries), processing image files through that model, and then performing network communications based on the extracted commands. This requires sophisticated behavioral analytics rather than simple rule-based detection.

Suggested Defensive Strategies:

  • Behavioral Anomaly Detection: Defenders should focus on detecting anomalous behavior on endpoints. This includes monitoring for Python processes that load machine learning libraries (like PyTorch, cryptography, hashlib, AES-256 in GCM mode) and then initiate unusual network connections or command executions.
  • Network Traffic Analysis for Context: While direct content inspection is hard, network traffic analysis can look for patterns:
  • Frequent, short-lived HTTP requests for image files from a compromised host.
  • Unusual image sizes or formats being consistently requested.
  • Correlation between image downloads and subsequent encrypted HTTP POST requests with specific parameters (cipher text, nonce, tag), even if their content cannot be decrypted.
  • Geographic anomalies in C2 server locations.
  • Dynamic Analysis and Sandboxing: Submitting suspicious images or executables to a sandboxed environment for dynamic analysis could reveal the true nature of the threat. If the client attempts to load an ML model and process images through it, this could be a strong indicator of compromise.
  • Threat Intelligence Sharing: The security community needs to actively share intelligence on such AI-driven C2 techniques, including indicators of compromise (IOCs) related to specific ML model structures or unique communication patterns observed.
  • AI-Assisted Detection: To combat AI-powered attacks, defenders may need to employ their own AI models. This could involve training models to identify subtle statistical anomalies in image files that might indicate hidden data, or to recognize the behavioral patterns of deep image steganography decoders. This is a challenging task, given the non-deterministic nature of the stego images.
  • Application Whitelisting and Control: Restricting the execution of unauthorized Python scripts or the loading of specific machine learning libraries on critical systems could mitigate the risk.
  • User and Entity Behavior Analytics (UEBA): Monitoring for unusual user activity, such as a user account suddenly executing Python scripts that download ML models or making outbound connections to suspicious domains, could provide early warning.

In essence, the rise of AI-powered steganography for C2 demands a shift from signature-based, static detection to more dynamic, behavioral, and context-aware defense mechanisms, potentially leveraging AI to counter AI.

Key Takeaways

  • Deep image steganography using neural networks is a practical and potent method for concealing C2 commands within images.
  • Specific data hiding, where the AI model is trained on a small, predefined set of payloads, achieves 100% command reconstruction with rapid training times ("less than 1 minute" for 100-bit payload) and small model sizes ("smaller than six megabytes").
  • This technique effectively bypasses signature-based detection because each stego image, even for the same command, appears visually identical but has a "slightly different" underlying pixel difference, making static signatures ineffective.
  • The non-linear operations of the AI decoder make it extremely difficult for defenders to reconstruct hidden payloads without access to the specific trained model.
  • The imageC2 prototype demonstrates a full AI-enhanced C2 framework, capable of downloading ML models and requirements.txt, retrieving stego images for commands like whoami and PowerShell reverse shells, and exfiltrating encrypted results over HTTP.
  • Defenders must shift from static, signature-based detection to behavioral anomaly detection, sophisticated network traffic analysis, and potentially AI-assisted detection to counter these evolving, AI-driven C2 threats.

About the Speaker(s)

Chen Fang is a Security Researcher at Palo Alto Networks. His work focuses on exploring advanced attack techniques, particularly those leveraging emerging technologies like artificial intelligence, and developing effective defensive strategies.

Chris Nawarte is a Principal Security Researcher at Palo Alto Networks. He specializes in identifying and analyzing novel threat vectors, with a strong emphasis on practical implementation and demonstration of sophisticated attack frameworks to inform and enhance cybersecurity defenses.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This talk presents a truly novel and deeply concerning C2 vector: deep image steganography powered by AI. The researchers didn't just wave their hands at 'AI-powered' hype; they delivered a practical, demonstrable framework (imageC2) that leverages specific data hiding to achieve 100% command reconstruction, rapid training, and a small model footprint. The critical insight that overfitting a model to specific payloads makes this viable for C2 is a game-changer, demonstrating a highly evasive technique that bypasses traditional detection and necessitates a fundamental shift in defensive thinking. This isn't just a theoretical exercise; it's a blueprint for the next generation of stealthy…

Heather Calloway (CISO) — STRONG ACCEPT

This presentation by Chen Fang and Chris Nawarte on AI-powered deep image steganography for C2 is a critically important wake-up call for security leadership. It demonstrates a practical, highly evasive method that bypasses traditional detection, directly challenging our assumptions about C2 visibility and control. The research clearly articulates a significant new vector that demands immediate attention to evolving our detection strategies from static signatures to sophisticated behavioral analytics and AI-assisted defense, directly impacting institutional resilience and risk ownership.

→ Top-rated talks at Black Hat Asia 2025

All talks from Black Hat Asia 2025