TA554TA554

Also known as: TA554 · TH-163

Known aliases
2

Profile

Since May 2018, Proofpoint researchers have observed email campaigns using a new downloader called sLoad. sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features. The malware gathers information about the infected system including a list of running processes, the presence of Outlook, and the presence of Citrix-related files. sLoad can also take screenshots and check the DNS cache for specific domains (e.g., targeted banks), as well as load external binaries. While initial versions of sLoad appeared in May 2018, we began tracking the campaigns from this actor (internally named TA554) since at least the beginning of 2017.

Aliases· 2

TA554TH-163

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA516
Actor
TA555
Actor
TA578
Actor
TA547
Actor
TA579
Actor
TA584
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.