zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Innovative Loader-as-a-Service Announced

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Innovative Loader-as-a-Service Announced

Product Serial: F-2024-02-07b

TLP:CLEAR

In this flash report, ZeroFox researchers report on a new malware loader-as-a-service offering gaining traction on the predominantly Russian-speaking dark web forum exploit[.]in. The currently unnamed loader allegedly targets Windows operating systems and is signed using valid certificates.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • Since its announcement on January 25, 2024, by untested actor “Null14”, an innovative malware loader-as-a-service offering has been gaining traction on the predominantly Russian-speaking dark web community exploit[.]in.
  • The currently unnamed loader allegedly targets Windows operating systems and is signed using valid certificates, enabling its deployment to remain undetected by various Windows systems as well as VirusTotal.
  • Although ZeroFox can neither confirm nor disconfirm the credibility of the service, positive indicators add credence to the legitimacy of this loader service as an innovative malware-spreading technique.
  • Malware distribution based on emulating credible software is likely on an upward trajectory, and this trend is expected to continue in the first half of 2024.

Tags: tlp:clear,  threat actor, malware