Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: TH-163

Description

Since May 2018, Proofpoint researchers have observed email campaigns using a new downloader called sLoad. sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features. The malware gathers information about the infected system including a list of running processes, the presence of Outlook, and the presence of Citrix-related files. sLoad can also take screenshots and check the DNS cache for specific domains (e.g., targeted banks), as well as load external binaries. While initial versions of sLoad appeared in May 2018, we began tracking the campaigns from this actor (internally named TA554) since at least the beginning of 2017.

AI Analysis

· 1 week ago

Executive Summary

TA554 (also known as TH-163) is a cyber threat actor observed since at least early 2017. This actor primarily uses sLoad, a PowerShell-based downloader that delivers Ramnit banker malware and includes advanced reconnaissance capabilities. TA554's campaigns have targeted financial institutions and organizations in the Asia-Pacific (APAC) and Europe-Middle East-Africa (EMEA) regions. The group demonstrates moderate sophistication with a focus on financial gain through banking Trojans and credential theft, using persistence techniques to maintain long-term access.

Goals & Targeting

TA554's primary goal appears to be financial gain through the distribution of banking Trojans and credential theft activities. The actor specifically targets financial institutions, focusing on organizations in the APAC and EMEA regions. This suggests that TA554 is likely seeking to compromise financial systems for unauthorized transactions or data exfiltration. The targeting of banks aligns with a common tactic seen in financially motivated APT groups, where compromising financial systems can yield high-value rewards. The actor's use of reconnaissance features in sLoad further indicates an intent to identify and target specific industries and organizations within those sectors.

Enhanced Description

TA554 has been actively operating since mid-2017, primarily targeting banks and financial institutions across APAC and EMEA regions. The actor's campaigns have increasingly relied on the sLoad malware, which is a PowerShell-based downloader designed to gather system information, take screenshots, and validate targeted domains (e.g., banking sectors). Initial versions of sLoad first appeared in May 2018, but Proofpoint tracking indicates earlier activity. TA554 has shown a preference for delivering Ramnit banker malware, suggesting a financial motivation. The actor's campaigns frequently involve email-based delivery mechanisms and demonstrate an ability to adapt their tools to avoid detection. In addition to sLoad, there are indicators of TA554 using Cobalt Strike in some operations, showcasing modular expertise with multiple attack frameworks.

Key Capabilities

  • Email-based campaigns using malicious scripts
  • sLoad malware for system reconnaissance and persistence
  • Ramnit banking Trojan distribution
  • Cobalt Strike for post-exploitation activities
  • Targeted domain validation via DNS cache checks

MITRE ATT&CK Tactics

Credential Access
Lateral Movement
Exfiltration
Defense Evasion

ATT&CK Techniques

T1059
T1078
T1003

Software / Tooling

sLoad
Ramnit Banker
Cobalt Strike

Campaigns & Victims

TA554 has been linked to multiple campaigns targeting financial institutions since 2017. The actor frequently uses email-based delivery mechanisms with malicious scripts, leveraging PowerShell for execution. Campaign activity appears to peak in intensity during certain times of the year, potentially coinciding with banking sector vulnerabilities or employee behavior patterns. Notable operations include the use of Ramnit banker malware and Cobalt Strike for post-exploitation activities. TA554 has demonstrated operational persistence across multiple years, suggesting a professional and organized approach to cyberattacks.

IOC Patterns

  • Email-based campaigns with malicious PowerShell scripts
  • Cobalt Strike C2 communication patterns
  • sLoad-related domain names in system DNS cache
  • RAMNIT banking Trojan file signatures
  • Network traffic originating from known Cobalt Strike beacon domains

Recommended Actions

  • Monitor email traffic for suspicious scripts and payloads using sandboxes or endpoint detection tools.
  • Block execution of untrusted scripts in email clients using AppLocker or similar tools.
  • Implement network monitoring for Cobalt Strike C2 activity and known malicious IP addresses.
  • Conduct regular employee training to identify phishing emails targeting financial sectors.
  • Enhance credential security using multi-factor authentication (MFA) where possible.
  • Deploy host-based intrusion detection systems (HIDS) to detect sLoad-related processes.

Suggested Tags

APT
banking Trojan
financial sector
APAC
EMEA

Confidence Assessment

Moderate confidence. TA554's activities are well-documented by Proofpoint, but specific details about its origins, motivations, and exact targeting criteria remain unclear. While sLoad and Ramnit distribution patterns suggest a financial focus, the actor's long-term operational persistence indicates moderate sophistication. Key gaps include an understanding of TA554's geographic origin and potential state-affiliation.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
banking Trojan
financial sector
APAC
EMEA

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.