SVCReady
MITRE ATT&CK: S1064 View on attack.mitre.org
Aliases: SVCReady
- First seen
- 2022-04-01 00:00:00
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 24 (24 malicious)
- Last IoC activity
- 2026-07-11 05:35:29
- Profile updated
- 2026-07-07 15:21:54
Context
SVCReady is a loader that has been used since at least April 2022 in malicious spam campaigns. Security researchers have noted overlaps between TA551 activity and SVCReady distribution, including similarities in file names, lure images, and identical grammatical errors.
Recent IoC activity
24 malicious indicators in Maltiverse are attributed to SVCReady (S1064). The 20 most recently updated:
Detection coverage
- 2 YARA rules
- 492 Sigma rules
Malware & tools used
- Query Registry (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Malicious File (attack-pattern)
- Data from Local System (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Visual Basic (attack-pattern)
- Rundll32 (attack-pattern)
- Scheduled Task (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Web Protocols (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Component Object Model Hijacking (attack-pattern)
- Screen Capture (attack-pattern)
- System Time Discovery (attack-pattern)
- Native API (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- System Information Discovery (attack-pattern)
- System Checks (attack-pattern)
- Process Discovery (attack-pattern)
- Software Discovery (attack-pattern)
- Time Based Checks (attack-pattern)
Detection rules
- MALPEDIA_Win_Svcready_Auto (yara-rule)
- SEKOIA_Loader_Win_Svcready_Imports (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Svcready (report)
- threatresearch.ext.hp.com — Svcready A New Loader Reveals Itself (report)
- socinvestigation.com — New Svcready Malware Loads From Word Doc Properties Detection Response (report)
- MITRE ATT&CK — S1064 (report)