EXECUTIVE SUMMARY
SSLoad is a sophisticated malware identified in recent phishing campaigns, known for its stealth and versatility. SSLoad infiltrates systems through decoy Word documents and phishing emails, ultimately deploying payloads like Cobalt Strike. The malware's varied delivery methods and technical complexity suggest its potential use in Malware-as-a-Service (MaaS) operations.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
SSLoad is a sophisticated malware identified in recent phishing campaigns, known for its stealth and versatility. SSLoad infiltrates systems through decoy Word documents and phishing emails, ultimately deploying payloads like Cobalt Strike. The malware's varied delivery methods and technical complexity suggest its potential use in Malware-as-a-Service (MaaS) operations.[emaillocker id="1283"]
The attack begins with the MSI installer, which initiates a chain of loaders culminating in the SSLoad payload. The primary loader, named "PhantomLoader," disguises itself as a legitimate DLL and uses self-modifying techniques to evade detection. PhantomLoader employs XOR encryption to decode the payload, which is then executed. The payload, a 32-bit DLL written in Rust, decrypts URLs and user agents, communicates with a Telegram channel for command-and-control (C2) purposes, and employs RC4 encryption for string decoding. The final payload, another Rust file, performs system reconnaissance, checks for debugging, dynamically loads libraries, and sends system fingerprints to the C2 server. It then awaits further commands from the C2, such as downloading additional payloads.
SSLoad's complexity, demonstrated through its multi-stage delivery process and use of advanced techniques like dynamic string decryption and anti-debugging measures, highlights the evolving nature of modern malware. The detailed analysis of SSLoad reveals its capability to gather reconnaissance data, evade detection, and deploy further payloads. This underscores the need for continuous monitoring and advanced threat detection methods to effectively counter such sophisticated threats. As SSLoad continues to evolve, it serves as a reminder of the critical importance of adaptive cybersecurity measures in protecting against dynamic and persistent malware campaigns.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1204 | User Execution |
| Persistence | T1574 | Hijack Execution Flow |
| Defense Evasion | T1036 | Masquerading |
| T1140 | Deobfuscate/Decode Files or Information | |
| T1055 | Process Injection | |
| T1070 | Indicator Removal | |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1082 | System Information Discovery |
| T1016 | System Network Configuration Discovery | |
| T1049 | System Network Connections Discovery | |
| Collection | T1005 | Data from Local System |
| Command and Control | T1573 | Encrypted Channel |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/06/cybercriminals-employ-phantomloader-to.html
[/emaillocker]