Target Industry

Primarily targets the pharmaceutical and the manufacturing sectors.

Overview

Researchers at Zscaler ThreatLabz have discovered a new malware called TransferLoader. The malware is particularly dangerous as it allows threat actors to execute arbitrary commands on compromised systems and deliver other malicious payloads. TransferLoader has been observed deploying Morpheus ransomware, targeting the legal sector in the United States. 

Impact

TransferLoader malware is likely to have a significant impact on organisations. This is due to its advanced capabilities and sophisticated evasion techniques. TransferLoader can cause significant operational disruptions, financial losses, and damage to reputation. The deployment of ransomware can lead to data encryption and demands for ransom payments. 

Exploitation

 phishing emails, malicious attachments, or compromised websites are usually used to deliver the downloader for the malware. After the downloader has been executed further payloads from a command-and-control (C2) server and various types of malwares are downloaded and installed on the compromised system. \

A backdoor module is then executed, enabling attackers to remotely execute arbitrary commands on the infected system. This module supports communication via HTTPS and raw TCP and uses the InterPlanetary File System (IPFS) for C2 communication.  

A specialised loader manages the configuration data for the backdoor and ensures the malware’s persistence. It also employs sophisticated evasion techniques, such as code obfuscation and anti-analysis method. The TransferLoader uses sophisticated methods to avoid detection, such as code obfuscation and anti-analysis techniques. 

Indicators of Compromise

The table below shows Indicators of Compromise (IoC) for the TransferLoader malware: 

IoC Type IoC Value Comment 
SHA-256 Hash 11d0b292ed6315c3bf47f5df4c7804edccbd0f6018777e530429cc7709ba6207 Hash value for TransferLoader backdoor loader 
SHA-256 Hash b8f00bd6cb8f004641ebc562e570685787f1851ecb53cd918bc6d08a1caae750 Hash value for TransferLoaderbackdoor 
SHA-256 Hash b55ba0f869f6408674ee9c5229f261e06ad1572c52eaa23f5a10389616d62efe Hash value for TransferLoader malware 
URL https://mainstomp[.]cloud/MDcMkjAxsLKsT URL for the downloader C2 server 
URL https://baza[.]com/loader.bin URL for the downloader C2 server 
URL https://temptransfer[.]live/SkwkUTIoFTrXYRMd URL for the downloader C2 server 
URL https://sharemoc[.]space/XdYUmFd2xX URL for the downloader C2 server 
URL https://ipfs[.]io/ipns/k51qzi5uqu5djqy6wp9nng1igaatx8nxwpye9iz18ce6b8ycihw8nt04khemao URL for the dIPFS updating the C2 servers of the backdoor module 

Containment, Mitigations & Remediations

To mitigate TransferLoader malware it is highly recommended to: 

Conduct regular training sessions to educate employees about phishing and malware threats. 

  • Ensure all systems and software are up-to-date with the latest security patches. 
  • Deploy robust endpoint security solutions to detect and block malware. 
  • Implement Intrusion Detection Systmes (IDS) to monitor network traffic for signs of malicious activity. 
  • Configure firewalls to block unauthorized access and suspicious connections.  
  • Perform regular backups of critical data to ensure recovery in case of ransomware attacks. 

Threat Landscape

Organisations within the primary targeted sectors are highly likely to be at severe risk of attack. This is due to the malware’s complex nature and its proficiency in avoiding detection. Recent reports indicate that the malware has been used in high-profile attacks, including one on an American law firm. 

Threat Group

The specific threat group behind the TransferLoader malware has not been identified at this time. 

Further Information

https://cybersecuritynews.com/transferloader-malware-allows-attackers-to-execute-arbitrary-commands/ 
https://www.zscaler.com/blogs/security-research/technical-analysis-transferloader?&web_view=true 

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content