SILKLOADER : Journey of a Cobalt Strike beacon loader along the silk road

Authors

Mohammad Kazem Hassan Nejad

Senior Threat Intelligence Researcher, WithSecure

Bert Steppé

Download report

Commercial and open-source command-and-control (C2) frameworks have become a staple in most adversary toolkits, with Cobalt Strike (CS) being one of the most popular. Such frameworks are often leveraged by threat actors to stage and conduct post-exploitation attacks in compromised client estates.

The prevalence of Cobalt Strike usage in attacks has precipitated a drive towards the creation of improved detection capabilities against it. Conversely, adversaries have responded to this by implementing their own detection evasion strategies. The most common of these include adding complexity to the auto-generated beacon or stager payloads via the utilization of packers, crypters, loaders, or similar techniques. While some threat actors rely on commercial crypters, others opt to develop their own custom crypters or take existing custom crypters into use.

During our investigations through several human-operated intrusions that resembled precursors to ransomware deployments, we came across an interesting Cobalt Strike beacon loader that leveraged DLL side-loading, which we’re tracking as SILKLOADER. By taking a closer look at the loader, we found several activity clusters leveraging this loader within the Russian as well as Chinese cybercriminal ecosystems.

In this report we share technical analysis of SILKLOADER and highlight notable activity clusters where it was seen in our investigations.

What next?

Discover WithSecure™ Elements Exposure Management.
– No credit card required. No obligations.No complexity.

Related Labs content

Find related content relating to this topic.

W/Labs

Attack Detection Software Protection Threat intelligence

DarkGate Rises: New version of DarkGate malware hunts like a Duck but bites like a RAT

On 4th August 2023, WithSecure Detection and Response Team (DRT) received an alert regarding spoofed process injection with abnormal memory characteristics on a host belonging to a WithSecure Countercept MDR customer.

W/Labs

Attack Detection Software Protection Threat intelligence

Reverse engineering a Lumma infection

Lumma is an information stealer that the WithSecure Detection and Response Team (DRT) have encountered several times. It has seen wider use over the past couple of years, and makes for an interesting threat to monitor.

W/Labs

AI security Attack Detection Software Protection

Machine learning-driven malware analysis

With the rapid emergence of new malware variants, accurately classifying and attributing malware samples has become more challenging than ever