Sophos reported that attackers used the Buer malware-as-a-service loader to gain initial access in a Ryuk ransomware intrusion, highlighting a shift in how Ryuk affiliates were reaching victims. The intrusion began with a low-volume spear-phishing campaign that used malicious documents hosted on Google Docs, and Buer was then used to deploy a Cobalt Strike beacon that enabled lateral movement before Ryuk ransomware was launched across the network.
The report said the activity later expanded into broader spam campaigns that also delivered other loaders, including Bazar and ZLoader, suggesting overlapping delivery infrastructure and coordinated lures. Sophos described Buer as a commercial loader for Windows that supports campaign management, victim filtering, and command-and-control tasking, and noted that observed samples used a stolen DigiCert code-signing certificate along with anti-analysis features and checks designed to avoid infecting systems in CIS-region countries.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A DigiCert-issued code-signing certificate for NEEDCODE SP Z O O was issued and was later used to digitally sign a Buer dropper observed in the Ryuk intrusion chain.
In September 2020, Sophos investigated a Ryuk ransomware intrusion in which attackers gained initial access through the Buer loader delivered via a malicious Google Docs-hosted document.
Buer was advertised on a forum on August 20, 2019 under the name "Modular Buer Loader," marking its introduction as a malware-as-a-service loader sold to cybercriminals.
Over the month following the initial low-volume spear-phishing activity, the campaign expanded into a larger spam operation delivering Buer along with other loaders including Bazar and ZLoader.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.