The Sasfis malware campaign used phishing emails posing as shipping invoices, delivery notices, and in some cases targeted tax-related messages to trick recipients into downloading malicious executables. Researchers described Sasfis as a command-driven bot client that contacted command-and-control infrastructure over HTTP-like and encrypted channels, then installed follow-on malware including Zeus banking trojans, keyloggers, password stealers such as Grabberz, FakeAV, and the Asprox/Dammec malware family. Early reporting also noted very low antivirus detection and anti-analysis behavior, including apparent blocking of traffic from known public sandbox IP addresses.
Later analysis found the botnet evolved quickly, improving resilience through custom packers, encrypted registry storage, RC4-encrypted command-and-control IP lists, and rotating dynamic IP pools. Sasfis was distributed through the Asprox spambot and increasingly shifted from attachment-based lures to image-based spam linking to hosted malware, while newer variants shared infrastructure with Asprox itself. Investigators also reported technical overlaps with the earlier Dofoil campaign, including similar code injection methods, the export name work, and server reuse shortly after Dofoil activity ended, suggesting a close operational link between the malware operations.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Fortinet reported that uptime for new Sasfis command-and-control servers had fallen from about one week in May 2012 to one or two days in September 2012. This reflected increasing churn in the campaign's infrastructure.
By early August 2012, Fortinet said the Sasfis botnet had already undergone five major changes. These included evolving packers, encrypted command-and-control communications, and mechanisms for rotating among possible C2 servers.
In early August 2012, the Asprox spambot changed from delivery-themed emails with executable attachments to emails containing an image that linked to a malicious executable hosted online. The article identifies Asprox as the sole spreading mechanism for the 2012 Sasfis campaign.
Fortinet researchers started tracking the 2012 Sasfis campaign after a surge of new samples appeared in late May 2012. The article also states Sasfis activity appeared on the same server IP shortly after Dofoil activity ended in May 2012, supporting a link between the two campaigns.
A SANS Internet Storm Center diary described Sasfis as a botnet payload used to install additional malware including Zeus, keyloggers, and fake antivirus, and noted distribution through phishing emails such as fake shipping invoices and a targeted tax-themed lure. The analysis also highlighted low antivirus detection and command-and-control activity involving v-medical.org and 89.187.53.203.
Trend Micro's threat encyclopedia states that SASFIS samples had been observed as early as 2009, establishing an earlier known appearance of the downloader than the current timeline reflects. The report describes SASFIS as a Windows Trojan downloader later used to install malware such as ZeuS and BREDOLAB.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
virusbulletin.com
Open sourcetrendmicro.com
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.