Sasfis, also tracked as OLDBAIT, is a Windows malware family primarily known as a Trojan downloader used to install additional malicious payloads on compromised systems. Public reporting has linked it to criminal operations associated with Smoky Spider, and it has been observed as part of broader botnet and pay-per-install ecosystems. Although sometimes described as a simple downloader, Sasfis has been used to enable follow-on infections by other malware families, including banking trojans, password stealers, spam bot components, and fake antivirus software.
Sasfis has been distributed through multiple delivery channels. Documented infection vectors include spam campaigns, phishing lures themed as delivery notices or trusted brands, executable attachments inside archive files, and drive-by compromise via websites using the Eleonore exploit pack. Campaign reporting from 2012 also tied Sasfis distribution to the Asprox spambot, which delivered malicious executables directly or via links embedded in email content. Some lures impersonated commercial or government-related services to induce execution.
On execution, Sasfis acts as a command-driven downloader and bot client. It can contact remote command infrastructure, register the infected host, poll for instructions, download and execute additional payloads, update itself, and remove itself. Reported command sets include functions for retrieving and launching malware as well as managing previously downloaded components. Some variants used encrypted communications and rotating command infrastructure, including RC4-protected server lists, to improve resilience.
Persistence has been observed through Windows autorun mechanisms, including Run-key style startup and Winlogon shell modification. Sasfis has also been described as memory-resident and capable of storing metadata related to downloaded payloads in encrypted registry data. Operationally, infections have been associated with monetization through pay-per-install and pay-per-access schemes, including redirection activity and installation of third-party malware on behalf of other operators.
Beyond its downloader role, OLDBAIT reporting also attributes credential theft capability to this malware family. It has been documented collecting credentials from web browsers such as Internet Explorer and Mozilla Firefox, as well as from multiple email clients including Eudora. This places Sasfis/OLDBAIT at the intersection of downloader activity and information theft, with compromised hosts exposed both to secondary malware delivery and direct credential compromise.
The malware targets Microsoft Windows systems, with reporting specifically identifying older Windows versions including Windows 2000, Windows XP, and Windows Server 2003. Its historical use in spam-driven criminal campaigns, botnet operations, and credential harvesting makes Sasfis a notable example of early modular cybercrime malware that combined initial compromise, persistence, payload delivery, and credential theft in a single ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Attributed to the criminal group Smoky Spider, a group that uses SmokeLoader and Sasfis, loader and downloader respectively.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Malware belonging to the SASFIS family are known to be downloaded on systems while visiting sites that have been compromised using a particular exploit pack known as "Eleonore".
Asprox initially used the name of a trusted delivery company as the bait to trick users into opening an executable email attachment with a document icon. In early August, however, it was observed that the spam had been improved by replacing the email content with an image containing the same text.
when a malicious executable such as FakeAV is downloaded through use of the c=rdl command, a registry entry will be created related to this downloaded file stored in the file system.
The injection technique provides a way to release the malicious code to a section and attach it to a suspended legitimate window process. The malicious code will be executed when the process is resumed in the end.
The new Sasfis is packed with a custom packer... the initial part of the custom packer consists of obfuscating instructions, sometimes combined with anti-debug or anti-virtual-environment techniques.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The injection technique provides a way to release the malicious code to a section and attach it to a suspended legitimate window process. The malicious code will be executed when the process is resumed in the end.
Winlogon Shell = "Explorer.exe rundll32.exe {4 random letters}.{3 random letters} {6 random letters]}"
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Evilnum can collect email credentials from victims... Malteiro has obtained credentials from mail clients via NirSoft MailPassView... MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software... PLEAD has the ability to steal saved passwords from Microsoft Outlook.
ips is the local IP of the botnet client (for collecting data on local network topology).
The payload of Sasfis acts as a listening client in the botnet operation... The traffic that would be accepted by the C&C server is described below: [C&C server URL]/forum/index.php?r=gate&id=XXXXXXX&group=XXXXX&debug=0
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sasfis is mentioned as a downloader used by the Smoky Spider criminal group alongside SmokeLoader.
Malware that collects credentials from browsers and email clients.
Malware that uses typo-squatted paths and filenames to mimic Microsoft Media Player components.
Malware that collects credentials from several email clients.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.