SSLoad is a Windows malware family used as an initial access payload in intrusion campaigns and botnet-linked operations. It has been observed delivered through phishing and malspam activity, including JavaScript-based infection chains and socially engineered lures that lead victims to execute malicious content. Reported delivery patterns include email-borne links, archive attachments, and ClickFix-style CAPTCHA impersonation workflows that induce user execution.
Once launched, SSLoad establishes command-and-control communications over HTTPS and performs host and domain reconnaissance, collecting system, user, and network information to help operators validate and triage compromised machines. Observed activity includes enumeration of local and domain context and transmission of collected reconnaissance to attacker-controlled infrastructure. In hands-on-keyboard intrusions, SSLoad has served as the foothold preceding deployment of additional tooling such as Cobalt Strike and remote management software, enabling broader post-compromise operations.
Campaign reporting links SSLoad-enabled intrusions to credential access, lateral movement, and full domain compromise in Windows enterprise environments. Operators have used follow-on tooling to harvest browser-stored credentials, dump LSASS, move to domain controllers and other critical servers, and create privileged accounts. SSLoad activity has also been associated with payload downloading and information-stealing behavior in malspam campaigns. The malware has been discussed in connection with TA578 and has appeared in broader criminal ecosystems overlapping with other loader and botnet operations. Victimology has included geographically diverse organizations, with observed targeting also extending to Ukrainian users in themed phishing campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New Actor for win.ssload ... description = "Detects win.ssload." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ssload"
New Actor for win.ssload ... description = "Detects win.ssload." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ssload"
New Actor for win.ssload ... description = "Detects win.ssload." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ssload"
New Actor for win.ssload ... description = "Detects win.ssload." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ssload"
14 distinct techniques documented for this family, organized by ATT&CK tactic.
After executing msiexec, the script then attempts to dismount the network drive.
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SSLoad is a loader malware used in botnet operations to deliver additional payloads, including ransomware.
Named as a malware family previously associated with the observed malspam distributor; the current campaign delivers a final payload with info-stealing and payload-downloading capabilities, but the content does not explicitly confirm SSLoad as the final payload.
The content is a YARA detection rule for win.ssload/Ssload, indicating it is a distinct malware family tracked by Malpedia. Based on the naming and rule context, it is treated as a Windows malware loader family, but the content does not provide behavioral detail beyond detection artifacts.
SSLoad is the primary malware in the campaign. It is delivered via phishing-linked JavaScript and MSI stages, then downloads and executes a DLL payload, beacons to C2 over HTTPS, collects host and domain information, and enables follow-on payload deployment, persistence, and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.