November 1, 2018 By Douglas Bonderud 2 min read

A PowerShell malware downloader known as sLoad is conducting targeted, geofenced attacks across the U.K., Italy and Canada.

According to researchers at Proofpoint, the most recent versions of sLoad — which has been active since at least May 2018 — targeted victims using sophisticated, multistep geodetection and fencing.

Once the ideal targets were identified, the attacks delivered the Ramnit banking Trojan to compromise accounts and steal financial data. Phishing emails were the infection vector of choice for these campaigns, with attackers preferring shipping or package notifications that included customized user names and other convincing details.

A Preference for Location Restriction and Reconnaissance

Target value now trumps sheer volume in malware campaigns. As noted by Proofpoint, the makers of sLoad performed multiple checks to ensure that targeted computers were within their preferred geographic area.

During five separate steps — the initial download of zipped LNK files, LNK files downloading PowerShell, PowerShell downloading sLoad, sLoad communicating with its command-and-control (C&C) server, and sLoad receiving tasks or commands — the malware performed a source IP check to verify the user’s location. During the initial PowerShell download and sLoad test receiving stages, the malware added additional “header fencing” to ensure that requests and Background Intelligent Transfer Service (BITS) data were identical.

While this campaign currently targets U.K., Canadian and Italian victims, minor geofencing adjustments could shift the delivery focus to other lucrative markets, making the threat a concern for companies everywhere.

Even when infected with sLoad, banking Trojans such as Ramnit aren’t installed immediately. Instead, this PowerShell malware gathers data about current processes, examines the use of Outlook and Citrix-related files, checks the Domain Name System (DNS) cache for targeted bank domains and takes screenshots that are returned to its C&C server. Once geographic location and favorable device environment are confirmed, sLoad delivers final payloads such as Ramnit, Gootkit or Ursnif.

How to Fend Off PowerShell Malware Attacks

The sLoad PowerShell malware includes a stealthy attack mechanism, customized phishing hooks and top-tier geofencing. Despite it’s sophisticated nature, however, the attack still relies on user action to jump-start the infection process. As a result, it’s possible to boost corporate defenses with the right email strategy. Security experts recommend conducting phishing simulations to identify weak points and implementing a layered defense approach that includes perimeter protection, managed security services (MSS) and improved employee awareness.

When it comes to the specific use of PowerShell, a recent report from IBM X-Force Incident Response and Intelligence Services (IRIS) noted that attacks are on the rise as threat actors recognize the value of executing code directly into memory. In these cases, better security starts with upgrading to PowerShell v5 to leverage its logging capabilities, turning on transcription logs to capture full commands, and monitoring for key events such as 4688 (new process creation) and 7045 (new service installed).

Source: Proofpoint

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today