Cybercriminals Employ PhantomLoader to Distribute SSLoad Malware
The loader PhantomLoader, which was previously undocumented, is being used to distribute the malware known as SSLoad, as per the research conducted by cybersecurity firm Intezer.
In a paper released this week, security experts Nicole Fishbein and Ryan Robinson stated, "The loader is added to a legitimate DLL, usually EDR or AV products, by binary patching the file and employing self-modifying techniques to evade detection."
Because of its various delivery methods, SSLoad is probably provided to other threat actors under a Malware-as-a-Service (MaaS) model. It uses phishing emails to penetrate networks, performs reconnaissance, and pushes more malware to victims read more Cybercriminals Employ PhantomLoader to Distribute SSLoad Malware.
Get up to date on the latest cybersecurity n...

