logo

Cybercriminals Employ PhantomLoader to Distribute SSLoad Malware

ID: 02b646be-ce5c-5893-94f0-f7df8afad973

STIX ID: report--02b646be-ce5c-5893-94f0-f7df8afad973

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-13

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Researchers reported a new malware family, SSLoad, delivered by a previously undocumented loader called PhantomLoader that hijacks legitimate DLLs (notably a 360 Total Security module) via binary patching. The infection chain often begins with an MSI installer that executes a 32-bit PhantomLoader which drops a Rust-based downloader and final payload; SSLoad fingerprints hosts, exfiltrates JSON-formatted reconnaissance data to a C2, and can fetch additional tools (including Cobalt Strike) with actor-controlled Telegram channels used as dead-drop resolvers. The campaign uses phishing to distribute SSLoad and other RATs (JScript RAT, Remcos) and employs anti-analysis and evasion techniques indicating a sophisticated, MaaS-style threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.