sLoad is a PowerShell-based downloader and trojanized delivery framework primarily associated with financially motivated email campaigns and best known for delivering the Ramnit banking Trojan. Activity involving sLoad has been tracked since 2018, notably in campaigns attributed to TA554, and later in phishing operations targeting organizations and users in countries including the United Kingdom, Italy, Canada, and Ukraine. It has been distributed through malspam and spearphishing lures such as package-delivery notices, order notifications, fake invoices, and impersonation of trusted institutions, often using archive files, deceptive shortcut files, or script-based droppers. Later campaigns also used VBScript-based staging components and abused compromised mail accounts.
A defining characteristic of sLoad is its extensive abuse of legitimate Windows administration and transfer mechanisms, especially the Background Intelligent Transfer Service, to download payloads, communicate with command-and-control infrastructure, and in some versions exfiltrate victim data. Infection chains commonly rely on PowerShell, scheduled tasks, and other living-off-the-land techniques to reduce visibility and maintain execution. Some observed variants also used auxiliary scripts or LOLBins to decode and launch additional binaries.
sLoad performs substantial host reconnaissance before or during payload delivery. Documented behaviors include collecting host and operating system information, enumerating running processes, checking for Outlook-related artifacts and Citrix ICA files, inspecting DNS cache entries for banking-related domains, enumerating network context, and capturing screenshots. It can beacon to command infrastructure, receive tasking, self-update, execute downloaded PowerShell, and retrieve and run additional executables. Multiple reports describe anti-analysis checks for security tools or analyst environments, and newer variants introduced infection-stage tracking so operators could classify compromised hosts and selectively assign follow-on payloads.
The malware has been repeatedly linked to delivery of banking malware, especially Ramnit, though other payload families have also appeared in broader TA554 delivery chains. In Ukraine-focused activity attributed to UAC-0050, sLoad was used in phishing campaigns themed around official correspondence and staged through archive and script chains. Across observed operations, sLoad has targeted Windows systems and has been used against business users, government-related entities, financial targets, and other organizations of operational or monetary interest.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Three days after, a new campaign was launched with the same IP located in Russia ... this time deploying the sLoad malware.
Since May 2018, Proofpoint researchers have observed email campaigns using a new downloader called sLoad. sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features.
Variant A (callsdk.online) Variant B (weekly-up.online) ... VT score 21/62 – Trojan.NukeSped 27/62 – Trojan.SLoad
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Il Cert-AgID ha riscontrato una nuova campagna massiva di malspam veicolata tramite PEC compromesse
Attached to the mail could be found a RAR archive, itself containing a ZIP archive unveiling a shortcut file (LNK).
The emails are crafted in the targeted country’s language and are often personalized to include recipients’ names and addresses in various parts of the email such as email body and subject. TA554 frequently uses package delivery or order notification lures; the emails contain URLs linking to zipped LNK files or zipped documents.
It then creates a scheduled task to run the .tmp file every 3 minutes, similar to the previous version.
The response can begin with: “run=” This is followed by a URL which is downloaded and its PowerShell content executed
The LNK file or document macros in turn download the next stage -- typically a PowerShell script which may download the final payload or another downloader such as sLoad.
Its purpose was to download a VBS script and a decoy PDF icon from the following folder.
BITSAdmin Abuse: MITRE Technique T1197. The malicious PowerShell script uses BITSAdmin to download sLoad from bureaucratica[.]org/bureaux/tica.
It then creates a scheduled task to run the .tmp file every 3 minutes, similar to the previous version.
with Starslord, the system information is encoded into Base64 data before being exfiltrated
The VBS script’s purpose was to download an obfuscated and weaponized version of the SSH client PuTTY.
Attached to the mail could be found a RAR archive, itself containing a ZIP archive unveiling a shortcut file (LNK). Its purpose was to download a VBS script and a decoy PDF icon.
Once launched, they would both download a SmokeLoader payload from the following URL, posing as a legitimate PuTTY executable.
After the executable is initiated, the malware hides its tracks using CMD with the del command to delete three files, including the encoded and decoded payloads.
The encoded payloads were decoded into a malicious executable using certutil.
BITSAdmin Abuse: MITRE Technique T1197. The malicious PowerShell script uses BITSAdmin to download sLoad from bureaucratica[.]org/bureaux/tica.
sLoad can also... check the DNS cache for specific domains (e.g., targeted banks)
Collection of information to report to the C&C server that includes: A list of running process
The malware gathers information about the infected system including a list of running processes, the presence of Outlook, and the presence of Citrix-related files.
If any files with .ICA extension are found on the system, searched starting from the “C:\users” folder... Whether an Outlook folder is present on the system
It also attempts to extract information about network shares and physical devices by using the NET VIEW command.
64 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A VBScript implant listed among the indicators of compromise as part of the malware set used in the campaign.
A VBScript implant/load-capable malware classification associated here with the Windows infection chain. It is described as part of a C2-enabled implant that performs Telegram-session checks, browser extension enumeration, and possible next-stage payload delivery.
VirusTotal classified one recovered Windows VBScript implant variant and one PowerShell loader variant as Trojan.SLoad. In this report it appears as an AV classification for campaign payload variants rather than the primary malware family under analysis.
PowerShell-based downloader/dropper used as the infection vector for Ramnit in this campaign. It is delivered via phishing and LOLBins, persists via scheduled task, performs reconnaissance and screen capture, steals ICA files, downloads and decodes payloads with BITSAdmin and certutil, uploads data to C2, and can also execute fileless PowerShell commands from remote servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.