Cybercriminals Employ PhantomLoader to Distribute SSLoad Malware
ID: 02b646be-ce5c-5893-94f0-f7df8afad973
STIX ID: report--02b646be-ce5c-5893-94f0-f7df8afad973
Feed Name: The Hacker News
Researchers reported a new malware family, SSLoad, delivered by a previously undocumented loader called PhantomLoader that hijacks legitimate DLLs (notably a 360 Total Security module) via binary patching. The infection chain often begins with an MSI installer that executes a 32-bit PhantomLoader which drops a Rust-based downloader and final payload; SSLoad fingerprints hosts, exfiltrates JSON-formatted reconnaissance data to a C2, and can fetch additional tools (including Cobalt Strike) with actor-controlled Telegram channels used as dead-drop resolvers. The campaign uses phishing to distribute SSLoad and other RATs (JScript RAT, Remcos) and employs anti-analysis and evasion techniques indicating a sophisticated, MaaS-style threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
