Cet article présente une analyse technique approfondie d’une nouvelle famille de malware baptisée Sauron Loader, découverte lors de plusieurs engagements clients en Allemagne. Le malware est vendu sous forme de Malware-as-a-Service (MaaS) dans des forums souterrains russes.
Sauron Loader
Sauron Loader is a Windows C++ malware loader observed in social-engineering campaigns against organizations in Germany.
Sauron Loader
Family profile
Sauron Loader is a Windows C++ malware loader observed in social-engineering campaigns against organizations in Germany. It has been delivered through ClickFix lures and vishing operations, including email bombing followed by callers impersonating IT support and persuading victims to initiate remote-assistance sessions. The malware has been advertised as a malware-as-a-service offering by an underground-forum user known as S4ur0n, reportedly for Russian-speaking criminal users; this advertising does not establish attribution for observed intrusions.
The loader uses DLL side-loading to execute encrypted malicious code in memory and establishes persistence using a recurring scheduled task. It incorporates execution delays and encrypted in-memory loading to impede automated analysis. Sauron Loader profiles infected systems, including host, user, operating-system, privilege, and installed-product details, and communicates with its controllers over encrypted HTTPS using custom Salsa20 encryption and RSA-based message authentication. It can retrieve and execute further payloads, including executables, DLLs, drivers, shellcode, installers, archives, command scripts, PowerShell, VBScript, and JavaScript. It can execute shellcode in memory or inject it into a process, install and start driver services, capture screenshots, and exfiltrate collected system data and screenshots through its command-and-control channel. Configuration logic includes keyboard-layout and public-sector checks reportedly intended to avoid CIS-region and public-sector targets.
Capabilities
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Initial Access
- Persistence
- Post Exploitation
- Process Injection
- Reconnaissance
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK