Sophos reported that attackers used the Buer malware-as-a-service loader to gain initial access in a Ryuk ransomware intrusion, highlighting a shift in how Ryuk affiliates were reaching victims. The intrusion began with a low-volume spear-phishing campaign that used malicious documents hosted on Google Docs, and Buer was then used to deploy a Cobalt Strike beacon that enabled lateral movement before Ryuk ransomware was launched across the network.
The report said the activity later expanded into broader spam campaigns that also delivered other loaders, including Bazar and ZLoader, suggesting overlapping delivery infrastructure and coordinated lures. Sophos described Buer as a commercial loader for Windows that supports campaign management, victim filtering, and command-and-control tasking, and noted that observed samples used a stolen DigiCert code-signing certificate along with anti-analysis features and checks designed to avoid infecting systems in CIS-region countries.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
A DigiCert-issued code-signing certificate for NEEDCODE SP Z O O was issued and was later used to digitally sign a Buer dropper observed in the Ryuk intrusion chain.
In September 2020, Sophos investigated a Ryuk ransomware intrusion in which attackers gained initial access through the Buer loader delivered via a malicious Google Docs-hosted document.
Buer was advertised on a forum on August 20, 2019 under the name "Modular Buer Loader," marking its introduction as a malware-as-a-service loader sold to cybercriminals.
Over the month following the initial low-volume spear-phishing activity, the campaign expanded into a larger spam operation delivering Buer along with other loaders including Bazar and ZLoader.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.