Threat Advisory

Cybercriminals Utilize PhantomLoader to Deploy SSLoad Malware

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

SSLoad is a sophisticated malware identified in recent phishing campaigns, known for its stealth and versatility. SSLoad infiltrates systems through decoy Word documents and phishing emails, ultimately deploying payloads like Cobalt Strike. The malware's varied delivery methods and technical complexity suggest its potential use in Malware-as-a-Service (MaaS) operations.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

SSLoad is a sophisticated malware identified in recent phishing campaigns, known for its stealth and versatility. SSLoad infiltrates systems through decoy Word documents and phishing emails, ultimately deploying payloads like Cobalt Strike. The malware's varied delivery methods and technical complexity suggest its potential use in Malware-as-a-Service (MaaS) operations.[emaillocker id="1283"]

The attack begins with the MSI installer, which initiates a chain of loaders culminating in the SSLoad payload. The primary loader, named "PhantomLoader," disguises itself as a legitimate DLL and uses self-modifying techniques to evade detection. PhantomLoader employs XOR encryption to decode the payload, which is then executed. The payload, a 32-bit DLL written in Rust, decrypts URLs and user agents, communicates with a Telegram channel for command-and-control (C2) purposes, and employs RC4 encryption for string decoding. The final payload, another Rust file, performs system reconnaissance, checks for debugging, dynamically loads libraries, and sends system fingerprints to the C2 server. It then awaits further commands from the C2, such as downloading additional payloads.

SSLoad's complexity, demonstrated through its multi-stage delivery process and use of advanced techniques like dynamic string decryption and anti-debugging measures, highlights the evolving nature of modern malware. The detailed analysis of SSLoad reveals its capability to gather reconnaissance data, evade detection, and deploy further payloads. This underscores the need for continuous monitoring and advanced threat detection methods to effectively counter such sophisticated threats. As SSLoad continues to evolve, it serves as a reminder of the critical importance of adaptive cybersecurity measures in protecting against dynamic and persistent malware campaigns.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1204 User Execution
Persistence T1574 Hijack Execution Flow
Defense Evasion T1036 Masquerading
T1140 Deobfuscate/Decode Files or Information
T1055 Process Injection
T1070 Indicator Removal
Credential Access T1003 OS Credential Dumping
Discovery T1082 System Information Discovery
T1016 System Network Configuration Discovery
T1049 System Network Connections Discovery
Collection T1005 Data from Local System
Command and Control T1573 Encrypted Channel

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/06/cybercriminals-employ-phantomloader-to.html

[/emaillocker]
crossmenu