Zloader
Aliases: DELoader, SILENTNIGHT, Terdot
- First seen
- 2016-05-01 00:00:00
- Malware type
- loader, trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:04:50
- Profile updated
- 2026-07-07 12:58:15
Targeted industries: financial-services
Context
This family describes the (initially small) loader, which downloads Zeus OpenSSL. In June 2016, a new loader was dubbed DEloader by Fortinet. It has some functions borrowed from Zeus 2.0.8.9 (e.g. the versioning, nrv2b, binstorage-labels), but more importantly, it downloaded a Zeus-like banking trojan (-> Zeus OpenSSL). Furthermore, the loader shared its versioning with the Zeus OpenSSL it downloaded. The initial samples from May 2016 were small (17920 bytes). At some point, visualEncrypt/Decrypt was added, e.g. in v1.11.0.0 (September 2016) with size 27648 bytes. In January 2017 with v1.15.0.0, obfuscation was added, which blew the size up to roughly 80k, and the loader became known as Zloader aka Terdot. These changes may be related to the Moskalvzapoe Distribution Network, which started the distribution of it at the same time. Please note that IBM X-Force decided to call win.zloader/win.zeus_openssl "Zeus Sphinx", after mentioning it as "a new version of Zeus Sphinx" in their initial post in August 2016. Malpedia thus lists the alias "Zeus XSphinx" for win.zeus_openssl - the X to refer to IBM X-Force.
Detection coverage
- 7 YARA rules
Used by threat actors
- Zloader & Ursnif Affiliate Campaign 2020-22 (campaign)
Detection rules
- RUSSIANPANDA_Win_Mal_Zloader (yara-rule)
- SIGNATURE_BASE_MAL_DOC_Zloader_Oct20_1 (yara-rule)
- CAPE_Zloader (yara-rule)
- CAPE_Zloader_2024 (yara-rule)
- CAPE_Zloader_1 (yara-rule)
- CAPE_Zloader2024 (yara-rule)
- CAPE_Zloader2025 (yara-rule)
Reports & references
- CrowdStrike — Report2021Gtr (report)
- CISA — Aa22 110A (report)
- decoded.avast.io — Avast Q2 2022 Threat Report (report)
- cloud.google.com — Unc4393 Goes Gently Into Silentnight (report)
- blog.malwarebytes.com — Malsmoke Operators Abandon Exploit Kits In Favor Of Social Engineering Scheme (report)
- cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- bleepingcomputer.com — Fake Microsoft Teams Updates Lead To Cobalt Strike Deployment (report)
- zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)
- labs.sentinelone.com — Enter The Maze Demystifying An Affiliate Involved In Maze Snow (report)
- Microsoft — Dismantling Zloader How Malicious Ads Led To Disabled Security Tools And Ransomware (report)
- guidepointsecurity.com — From Zloader To Darkside A Ransomware Story (report)
- deepinstinct.com — Deep Dive Packing Software Cryptone (report)
- mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
- Cisco Talos — 2020 Year In Malware (report)
- mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
- noticeofpleadings.com — 1%20 Microsoft%20Cobalt%20Strike%20 %20Complaint(907040021.9) (report)
- CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- umbrella.cisco.com — Cybersecurity Threat Spotlight Strrat Zloader Honeygain (report)
- cybereason.com — Threat Analysis Report Socgholish And Zloader From Fake Updates And Installers To Owning Your Systems (report)