TA554 is a threat group using the sLoad PowerShell downloader to deliver the Ramnit banking trojan to the financial sector.
Analyst brief
TA554, also tracked as TH-163, is a threat group active since at least 2017 that leverages a PowerShell downloader called sLoad in email campaigns. They primarily target the financial sector to deliver the Ramnit banking trojan, with sLoad performing extensive reconnaissance such as checking running processes, Outlook and Citrix file presence, and DNS cache lookups for targeted bank domains. The group’s key TTPs include phishing emails with the sLoad downloader, PowerShell obfuscation, and system profiling via screenshots and external binary loading. Defenders should focus on monitoring PowerShell execution, scrutinizing email-borne downloaders, analyzing DNS queries for banking-related domains, and tracking C2 indicators tied to Ramnit infections.
TA554
TH-163
unknown
Since May 2018, Proofpoint researchers have observed email campaigns using a new downloader called sLoad. sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features. The malware gathers information about the infected system including a list of running processes, the presence of Outlook, and the presence of Citrix-related files. sLoad can also take screenshots and check the DNS cache for specific domains (e.g., targeted banks), as well as load external binaries.
While initial versions of sLoad appeared in May 2018, we began tracking the campaigns from this actor (internally named TA554) since at least the beginning of 2017.
What malware does TA554 deliver using the sLoad downloader?+
TA554 uses the sLoad PowerShell downloader most frequently to deliver the Ramnit banking trojan.
What reconnaissance activities does sLoad perform on an infected system?+
sLoad gathers a list of running processes, checks for the presence of Outlook and Citrix-related files, takes screenshots, checks the DNS cache for specific bank domains, and can load external binaries.