Targeted intrusion campaigns used tampered Microsoft-signed DLLs to evade trust checks and launch malware through DLL side-loading and service hijacking. LAC researchers documented the SigLoader malware family modifying data in a file's certificate or overlay area while preserving Windows signature validation, allowing the DLL to still appear legitimately signed. The loader then decrypted and executed additional stages in memory using layered routines including XOR, custom DES, AES, and later RC4, with observed payloads including DelfsCake, GreetCake, and shellcode associated with Metasploit Framework or Cobalt Strike. In one case, the intrusion began with exploitation of an SSL-VPN vulnerability before the loader was deployed on a compromised endpoint.
A related campaign assessed as likely tied to APT41 used the same signed-DLL abuse technique to deliver Cobalt Strike Beacon, including a tampered KBDTAM131.DLL derived from UXLibRes.dll and malicious loading via the Windows IKEEXT service and wlbsctrl.dll. Researchers said the loader stored encrypted configuration data, API strings, offsets, and payload content with ChaCha20, then decrypted a Beacon linked to a leaked or cracked Cobalt Strike 4.x build using watermark 0x12345678 and C2 over HTTPS, with other samples using HTTP or DNS. The activity was also tied to a malicious shortcut file masquerading as a PDF, campaign infrastructure including 119.45.238[.]189 and 192.109.98[.]187, and detection guidance using Sigcheck, Autoruns, Windows event logs, YARA rules, and stricter Authenticode verification.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
LAC published analysis of a separate malware family that abused Microsoft-signed DLL files to decrypt and execute embedded Cobalt Strike Beacon payloads. The report assessed the activity as highly likely associated with APT41 based on similarities with FireEye's March 2020 reporting and overlapping tradecraft.
LAC said it continued to observe attacks using SigLoader, also known as DESLoader or Ecipekac, in 2021. This established that the malware family remained active beyond the initial 2020 observations.
LAC released an emergency report detailing SigLoader's abuse of Microsoft-signed DLL files, certificate table tampering, multi-stage decryption, and in-memory execution. The report also documented one intrusion path involving exploitation of an SSL-VPN vulnerability before SigLoader deployment.
On December 1, 2020, a Twitter user publicly suggested that the actor using SigLoader might be APT10. LAC noted the speculation but did not confirm the attribution in its report.
As of November 20, 2020, researchers had confirmed three types of final payloads delivered by SigLoader. These included DelfsCake, GreetCake, and shellcode generated with Metasploit Framework or Cobalt Strike.
Passive DNS data cited by LAC indicated infrastructure at 119.45.238[.]189 was used as a C2 server or tool repository in late November 2020. This activity was tied to the same Cobalt Strike loader campaign abusing Microsoft-signed DLLs.
LAC identified a malicious shortcut file named "Top-up Scheme_Member List as of 20201022v1_for Nomination.pdf.lnk" that acted as a downloader for a Cobalt Strike Beacon named const.exe. The filename itself anchors the lure to October 22, 2020.
Passive DNS data cited by LAC showed infrastructure at 192.109.98[.]187 was used in related campaign activity in late October 2020. The infrastructure was associated with the Microsoft-signed DLL-abusing Cobalt Strike loader campaign later assessed as likely tied to APT41.
LAC reported observing targeted attacks using the SigLoader malware loader from around July 2020. The loader abused Microsoft-signed DLL files and DLL side-loading to evade detection and execute payloads in memory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
lac.co.jp
Open sourcelac.co.jp
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.