Target Industry
Primarily targets the pharmaceutical and the manufacturing sectors.
Overview
Researchers at Zscaler ThreatLabz have discovered a new malware called TransferLoader. The malware is particularly dangerous as it allows threat actors to execute arbitrary commands on compromised systems and deliver other malicious payloads. TransferLoader has been observed deploying Morpheus ransomware, targeting the legal sector in the United States.
Impact
TransferLoader malware is likely to have a significant impact on organisations. This is due to its advanced capabilities and sophisticated evasion techniques. TransferLoader can cause significant operational disruptions, financial losses, and damage to reputation. The deployment of ransomware can lead to data encryption and demands for ransom payments.
Exploitation
phishing emails, malicious attachments, or compromised websites are usually used to deliver the downloader for the malware. After the downloader has been executed further payloads from a command-and-control (C2) server and various types of malwares are downloaded and installed on the compromised system. \
A backdoor module is then executed, enabling attackers to remotely execute arbitrary commands on the infected system. This module supports communication via HTTPS and raw TCP and uses the InterPlanetary File System (IPFS) for C2 communication.
A specialised loader manages the configuration data for the backdoor and ensures the malware’s persistence. It also employs sophisticated evasion techniques, such as code obfuscation and anti-analysis method. The TransferLoader uses sophisticated methods to avoid detection, such as code obfuscation and anti-analysis techniques.
Indicators of Compromise
The table below shows Indicators of Compromise (IoC) for the TransferLoader malware:
| IoC Type | IoC Value | Comment |
| SHA-256 Hash | 11d0b292ed6315c3bf47f5df4c7804edccbd0f6018777e530429cc7709ba6207 | Hash value for TransferLoader backdoor loader |
| SHA-256 Hash | b8f00bd6cb8f004641ebc562e570685787f1851ecb53cd918bc6d08a1caae750 | Hash value for TransferLoaderbackdoor |
| SHA-256 Hash | b55ba0f869f6408674ee9c5229f261e06ad1572c52eaa23f5a10389616d62efe | Hash value for TransferLoader malware |
| URL | https://mainstomp[.]cloud/MDcMkjAxsLKsT | URL for the downloader C2 server |
| URL | https://baza[.]com/loader.bin | URL for the downloader C2 server |
| URL | https://temptransfer[.]live/SkwkUTIoFTrXYRMd | URL for the downloader C2 server |
| URL | https://sharemoc[.]space/XdYUmFd2xX | URL for the downloader C2 server |
| URL | https://ipfs[.]io/ipns/k51qzi5uqu5djqy6wp9nng1igaatx8nxwpye9iz18ce6b8ycihw8nt04khemao | URL for the dIPFS updating the C2 servers of the backdoor module |
Containment, Mitigations & Remediations
To mitigate TransferLoader malware it is highly recommended to:
Conduct regular training sessions to educate employees about phishing and malware threats.
- Ensure all systems and software are up-to-date with the latest security patches.
- Deploy robust endpoint security solutions to detect and block malware.
- Implement Intrusion Detection Systmes (IDS) to monitor network traffic for signs of malicious activity.
- Configure firewalls to block unauthorized access and suspicious connections.
- Perform regular backups of critical data to ensure recovery in case of ransomware attacks.
Threat Landscape
Organisations within the primary targeted sectors are highly likely to be at severe risk of attack. This is due to the malware’s complex nature and its proficiency in avoiding detection. Recent reports indicate that the malware has been used in high-profile attacks, including one on an American law firm.
Threat Group
The specific threat group behind the TransferLoader malware has not been identified at this time.
Further Information
https://cybersecuritynews.com/transferloader-malware-allows-attackers-to-execute-arbitrary-commands/
https://www.zscaler.com/blogs/security-research/technical-analysis-transferloader?&web_view=true













