Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cet article présente une analyse technique approfondie d’une nouvelle famille de malware baptisée Sauron Loader, découverte lors de plusieurs engagements clients en Allemagne. Le malware est vendu sous forme de Malware-as-a-Service (MaaS) dans des forums souterrains russes.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
T1027.007 — Obfuscated Files or Information: Dynamic API Resolution (Defense Evasion).
rnp.dll : DLL malveillante contenant la fonctionnalité principale du loader (chiffrée).
Le malware dépose rnpkeys.exe, binaire légitime de la suite Mozilla RNPGP, et rnp.dll dans C:\ProgramData\keyroll.
T1055.012 — Process Injection: Process Hollowing (Defense Evasion).
tdwp.dll : DLL responsable du déchiffrement en mémoire et de la persistance.
Le loader communique via HTTPS POST avec des chemins générés aléatoirement.
Le loader supporte l’exécution de multiples formats de payload : EXE, DLL, Driver, Shellcode, MSI, ZIP, CMD, PowerShell, VBS et JavaScript.
Les attaquants incitent les victimes à initier des sessions Microsoft Quick Assist ou AnyDesk.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C++ MSI-based loader sold as a MaaS offering to Russian-speaking cybercriminals. It uses DLL side-loading through a legitimate Mozilla RNPGP binary, maintains persistence with a scheduled task, evades analysis through execution delays and CIS keyboard-layout checks, and uses encrypted HTTPS C2. It can execute EXE, DLL, driver, shellcode, MSI, archive, and scripting payloads; capture screenshots; collect system information; and exfiltrate data over C2.
A C++ Windows loader sold as MaaS to Russian-speaking cybercriminals. It uses DLL side-loading and a scheduled task for persistence, decrypts its in-memory loader code and configuration, registers hosts and polls HTTPS C2 infrastructure, executes numerous payload types, and can capture and exfiltrate screenshots.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.