RockLoader is a Windows malware family used primarily as an intermediate downloader or loader in large-scale financially motivated email campaigns. It emerged in 2016 and is closely associated with TA505, which used it extensively in Locky ransomware operations and also employed it to deliver additional payloads including Dridex, Pony, and Kegotip. RockLoader has also been linked to distribution activity via the Necurs botnet.
RockLoader was commonly delivered through malicious spam using JavaScript attachments and weaponized document attachments, often embedded in archive files and accompanied by obfuscation and formatting tricks intended to evade email security controls. In TA505 operations, it functioned as a staging component that retrieved follow-on malware from command-and-control infrastructure rather than serving as the final payload itself.
The malware uses encrypted command-and-control communications and supports tasking to fetch and execute additional content. Reported functionality includes updating itself, deleting itself, and decrypting downloaded payloads. Later variants incorporated XOR-based obfuscation for API resolution and embedded components to bypass User Account Control on both 32-bit and 64-bit Windows systems, indicating active development and a focus on defense evasion and reliable execution.
RockLoader has also been observed using self-signed SSL/TLS certificates in its command-and-control communications, consistent with broader efforts by malware operators to conceal traffic within encrypted sessions. Its role as a flexible intermediary delivery mechanism, combined with TA505’s high-volume spam infrastructure, made it an important component in mid-2010s malware distribution campaigns targeting organizations at scale, including campaigns observed against entities in Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA505 first introduced Rockloader in April 2016 as an intermediate loader for Locky.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
In recent weeks, we detected a marked increase in email campaigns attempting to install Locky... This particular campaign... used malicious document attachments... Outside of the very large campaign detected on April 7th, the ransomware in many of these campaigns is being installed via JavaScript attachment files rather than documents.
This particular campaign, primarily targeting UK and French organizations, used malicious document attachments and a new malware variant we are calling RockLoader... the ransomware in many of these campaigns is being installed via JavaScript attachment files rather than documents.
On 64-bit systems an executable is extracted and run which performs SetWindowsHookEx-based DLL injection into explorer using a DLL contained in the binary’s resources... On 32-bit operating systems, the DLL injection is performed via the same method from the original RockLoader binary itself.
In addition to the use of Rockloader, threat actors distributing Locky have been using an array of obfuscation techniques... Increasingly convoluted JavaScript obfuscation... The specific JavaScript that downloads Locky uses obfuscation techniques including character substitution, string concatenation, dead code, integer to character conversion, and other tricks.
The downloader’s runtime API resolution code has been modified to obfuscate the names of APIs being resolved using a simple 8-byte XOR algorithm... Some APIs that were static imports before, such as ShellExecuteA, are now resolved dynamically.
On 64-bit systems an executable is extracted and run which performs SetWindowsHookEx-based DLL injection into explorer using a DLL contained in the binary’s resources... On 32-bit operating systems, the DLL injection is performed via the same method from the original RockLoader binary itself.
Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
This actor is frequently using it as an intermediate “downloader”. This downloader has been distributed both through JavaScript attachments and malicious documents and, in turn, downloads Locky... on April 6th and 7th, 2016, we spotted this downloader being used to load other malware including Dridex 220, Pony, and Kegotip.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
Intermediate loader initially delivered by attached JavaScript; used to download Locky and sometimes Pony and Kegotip.
Malware distributed by the Necurs botnet (further details not provided in the content).
Intermediate downloader under active development that is delivered via JavaScript attachments and malicious documents, communicates with a C2 server using encrypted traffic, can download and execute Locky and other malware, supports update/delete/tasking commands, and includes UAC bypass capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.