SVCReady

MITRE ATT&CK: S1064 View on attack.mitre.org

Aliases: SVCReady

First seen
2022-04-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Related IoCs
24 (24 malicious)
Last IoC activity
2026-07-11 05:35:29
Profile updated
2026-07-07 15:21:54

Context

SVCReady is a loader that has been used since at least April 2022 in malicious spam campaigns. Security researchers have noted overlaps between TA551 activity and SVCReady distribution, including similarities in file names, lure images, and identical grammatical errors.

Recent IoC activity

24 malicious indicators in Maltiverse are attributed to SVCReady (S1064). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample yB038.tmp.bin 2026-07-11 2
file sample agenziapiu,invoice,12.05.22.doc 2026-06-26 1
file sample isifim-invoice-12.05.doc 2026-05-03 1
file sample y31FF.tmp.dll 2026-04-30 1
file sample sinergieadv.document.12.05.2022.doc 2026-04-26 1
file sample crismasrl.document.12.05.22.doc 2026-04-26 1
file sample unimare,doc,19.05.2022.doc 2026-04-23 1
file sample almabike_document_17.06.2022.doc 2026-03-13 1
file sample assorestauro file 17.06.doc 2026-02-18 1
file sample ireplace-file-08.06.22.doc 2026-01-09 1
file sample itiscalfaro.cz_file_12.05.2022.doc 2025-11-13 1
file sample fisem,document,12.05.2022.doc 2025-11-09 1
file sample tuttoverdeshop-file-25.05.2022.doc 2025-11-09 1
file sample mistershut,file,08.06.22.doc 2025-10-14 1
file sample pastagentile,file,08.06.22.doc 2025-10-03 1
file sample avvpghizzoni doc 13.06.22.doc 2025-10-02 1
file sample bikealma_document_20.06.2022.doc 2025-09-23 1
file sample varacalli-file-13.06.2022.doc 2025-09-23 1
file sample agsolbiatearno-doc-17.06.22.doc 2025-09-16 1
file sample cammino-invoice-12.05.22.doc 2025-02-16 1

Detection coverage

  • 2 YARA rules
  • 492 Sigma rules

Malware & tools used

  • Query Registry (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Malicious File (attack-pattern)
  • Data from Local System (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Visual Basic (attack-pattern)
  • Rundll32 (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Web Protocols (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Component Object Model Hijacking (attack-pattern)
  • Screen Capture (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • System Information Discovery (attack-pattern)
  • System Checks (attack-pattern)
  • Process Discovery (attack-pattern)
  • Software Discovery (attack-pattern)
  • Time Based Checks (attack-pattern)

Detection rules

  • MALPEDIA_Win_Svcready_Auto (yara-rule)
  • SEKOIA_Loader_Win_Svcready_Imports (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Svcready (report)
  • threatresearch.ext.hp.com — Svcready A New Loader Reveals Itself (report)
  • socinvestigation.com — New Svcready Malware Loads From Word Doc Properties Detection Response (report)
  • MITRE ATT&CK — S1064 (report)

External references