Proofpoint reported that threat actor TA554 ran sustained email campaigns targeting organizations and users in the United Kingdom, Italy, and Canada, using localized package-delivery and order-notification lures to distribute malware. The campaigns relied heavily on zipped .LNK shortcut files, a Windows Shell Link format documented by Microsoft, to start the infection chain and launch PowerShell-based retrieval of additional payloads. TA554 also applied geofencing and personalization throughout the operation to improve targeting and reduce unnecessary exposure.
Once executed, the sLoad downloader performed broad host reconnaissance, including process enumeration, checks for Outlook and Citrix artifacts, DNS-cache inspection for banking domains, screenshot capture, and support for loading external binaries. Proofpoint said sLoad beaconed to command-and-control infrastructure over HTTP, reported victim details through request parameters, polled for follow-on commands, and could update itself; in many cases it later delivered the Ramnit banking trojan after a delay. The actor also evolved its tradecraft during the campaign, shifting from LNK files that fetched intermediate PowerShell stages to LNK files that downloaded sLoad directly.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft published analysis of sLoad version 2.0, which it called 'Starslord,' describing new infection-stage tracking and a checkUniverse anti-analysis mechanism that separates suspected analyst machines from real victims. The research also noted that non-trapped hosts were intermittently receiving the Ramnit file infector.
Proofpoint observed sLoad version 5.08b on 2018-10-03, indicating continued iteration of the downloader during the campaign.
Proofpoint reported seeing sLoad version 0.01b on 2018-05-01, providing an early dated anchor for the malware's development and use in the campaign.
Proofpoint researchers observed TA554 using the PowerShell downloader sLoad in email campaigns beginning in May 2018. These campaigns primarily targeted recipients in the United Kingdom, Italy, and Canada and often used localized package-delivery or order-notification lures.
Cybereason investigated a customer intrusion in which an Italian spam campaign delivered the sLoad downloader and ultimately a Ramnit banking Trojan variant. The report detailed abuse of LOLBins including PowerShell, BITSAdmin, and certutil, plus persistence, reconnaissance, screenshot exfiltration, Citrix ICA file hunting, and reflective injection components used by Ramnit.
Proofpoint published research detailing sustained TA554 campaigns using sLoad to deliver malware including Ramnit, along with technical analysis of the infection chain, geofencing, reconnaissance, and command-and-control behavior.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
msdn.microsoft.com
Open sourcecybereason.com
Open sourcemicrosoft.com
Open sourceproofpoint.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.