Also known as: TH-163
Since May 2018, Proofpoint researchers have observed email campaigns using a new downloader called sLoad. sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features. The malware gathers information about the infected system including a list of running processes, the presence of Outlook, and the presence of Citrix-related files. sLoad can also take screenshots and check the DNS cache for specific domains (e.g., targeted banks), as well as load external binaries. While initial versions of sLoad appeared in May 2018, we began tracking the campaigns from this actor (internally named TA554) since at least the beginning of 2017.
Executive Summary
TA554 (also known as TH-163) is a cyber threat actor observed since at least early 2017. This actor primarily uses sLoad, a PowerShell-based downloader that delivers Ramnit banker malware and includes advanced reconnaissance capabilities. TA554's campaigns have targeted financial institutions and organizations in the Asia-Pacific (APAC) and Europe-Middle East-Africa (EMEA) regions. The group demonstrates moderate sophistication with a focus on financial gain through banking Trojans and credential theft, using persistence techniques to maintain long-term access.
Goals & Targeting
TA554's primary goal appears to be financial gain through the distribution of banking Trojans and credential theft activities. The actor specifically targets financial institutions, focusing on organizations in the APAC and EMEA regions. This suggests that TA554 is likely seeking to compromise financial systems for unauthorized transactions or data exfiltration. The targeting of banks aligns with a common tactic seen in financially motivated APT groups, where compromising financial systems can yield high-value rewards. The actor's use of reconnaissance features in sLoad further indicates an intent to identify and target specific industries and organizations within those sectors.
Enhanced Description
TA554 has been actively operating since mid-2017, primarily targeting banks and financial institutions across APAC and EMEA regions. The actor's campaigns have increasingly relied on the sLoad malware, which is a PowerShell-based downloader designed to gather system information, take screenshots, and validate targeted domains (e.g., banking sectors). Initial versions of sLoad first appeared in May 2018, but Proofpoint tracking indicates earlier activity. TA554 has shown a preference for delivering Ramnit banker malware, suggesting a financial motivation. The actor's campaigns frequently involve email-based delivery mechanisms and demonstrate an ability to adapt their tools to avoid detection. In addition to sLoad, there are indicators of TA554 using Cobalt Strike in some operations, showcasing modular expertise with multiple attack frameworks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA554 has been linked to multiple campaigns targeting financial institutions since 2017. The actor frequently uses email-based delivery mechanisms with malicious scripts, leveraging PowerShell for execution. Campaign activity appears to peak in intensity during certain times of the year, potentially coinciding with banking sector vulnerabilities or employee behavior patterns. Notable operations include the use of Ramnit banker malware and Cobalt Strike for post-exploitation activities. TA554 has demonstrated operational persistence across multiple years, suggesting a professional and organized approach to cyberattacks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence. TA554's activities are well-documented by Proofpoint, but specific details about its origins, motivations, and exact targeting criteria remain unclear. While sLoad and Ramnit distribution patterns suggest a financial focus, the actor's long-term operational persistence indicates moderate sophistication. Key gaps include an understanding of TA554's geographic origin and potential state-affiliation.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics