Blog

Chinese SilkLoader Malware Sold to Russian Cyber-Criminals

SILKLOADER is a Chinese Cobalt Strike Beacon Loader sold to Russian cyber-criminals. It was used in numerous attacks uncovered by Walmart Global Tech and SentinelLabs, such as those targeting Trickbot banking Trojan operators and Hancitor (MAN1/Moskalvzapoe/TA511) group members. The SILKLOADER malware is an executable file that loads several libraries during its runtime and generates Cobalt […]
PX
Propelex team May 18, 2023 - 7 minutes read

SILKLOADER is a Chinese Cobalt Strike Beacon Loader sold to Russian cyber-criminals. It was used in numerous attacks uncovered by Walmart Global Tech and SentinelLabs, such as those targeting Trickbot banking Trojan operators and Hancitor (MAN1/Moskalvzapoe/TA511) group members.

The SILKLOADER malware is an executable file that loads several libraries during its runtime and generates Cobalt Strike beacon traffic according to embedded configuration data. Its primary goal is to send command and control (C2) traffic from victim machines to an attacker-controlled server using HTTP host header information provided in the beacon’s configuration data.

SILKLOADER is a Cobalt Strike Beacon Loader

The cybercrime landscape is evolving quickly. Over the past year, we’ve observed a shift in how gangs operate – from traffic generation to malware distribution, financial crimes and network access management.

For a cybergang to be successful, they require specialists in various fields. This means recruiting management personnel, malware operators and experts in network access and financial extraction.

Proofpoint notes that this tool has been exploited by threat actors to hide malicious traffic among legitimate requests and avoid network detections. It’s customizable with a malleable C2 profile that permits malicious actors to alter lateral options like pipe names or domain names for Beacon’s C2 servers.

Most Beacon instances use a unique pipe, but operators can define their own malleable profiles to select different pipe names for their deployments. Furthermore, they have the freedom to select multiple URL paths and customize their BEACON shellcode accordingly.

Researchers at NCCGroup have discovered that the BEACON keys used in Cobalt Strike’s Beacon Loader are stored in a serialized file called.cobaltstrike.beacon_keys in the team server working directory. With this information, security analysts can detect illegitimate copies of software by comparing its watermark in this keystore with that stored for each payload’s public key.

Researchers have also observed cases where two payloads originate from the same team server, yet use different URL paths in their payloads. This could be indicative of malicious actors distributing multiple copies of a Cobalt Strike Beacon loader and altering its watermark in.cobaltstrike.beacon_keys file during cracking operations.

Threat actors possess the capability to register fake beacons with Cobalt Strike’s server, which could potentially crash it by exhausting its available memory and stopping new beacons from being installed on infected machines and interfering with red team operations that deployed them. Furthermore, this capability allows Cobalt Strike to block communication with its C2 server during infection campaigns.

SILKLOADER is a DLL Side-Loader

Cybercriminals often employ DLL side-loading in an attempt to avoid detection. This method takes advantage of how Windows applications handle DLL files, allowing malicious DLLs to load and execute without any checks by either the operating system or security product installed on the victim’s computer.

DLL side-loading has long been a nuisance to security products, but is becoming more commonplace among threat actors as a means of orchestrating ransomware attacks. Malware authors also employ this technique to steal information and deliver tools for lateral movement across compromised networks.

One of the most sophisticated DLL side-loading attacks to date seeks to bypass Windows’ default search order and take advantage of weak library references by planting a malicious DLL file into the WinSxS directory on the system. Once loaded, this malicious DLL will execute an additional stage malware loader automatically.

Another attack uses DLL side-loading to avoid detection by planting an unsigned executable alongside the malicious DLL in the target directory. This technique is commonly employed by malware creators to plant malicious DLLs in target directories and use them for running worms or backdoors that later lead to further compromises.

Researchers at X-Force have observed this technique being employed by Metamorfo, a banking Trojan that drops both a DLL and signed executable to install a backdoor. It has also been observed in other attacks such as ransomware operators planting the DLL and signed executable together in the target folder to launch their payload.

DLL side-loading attacks are frequently used to avoid detection by antivirus programs. They take advantage of the fact that when an application loads a DLL, its operating system first searches in its installation directory before loading it from Windows Side-by-Side directory.

These threats utilize a custom loader to bypass detection by Windows and run the Sodamaster backdoor. This tool has been in operation since at least 2020 and features several defense evasion features as well as being capable of executing shellcode in memory, enabling it to avoid detection when looking in the registry or delaying execution.

SILKLOADER is a Packer-as-a-Service

One of the most profitable malware sales and subscription models in cybercrime is malware-as-a-service (MaaS). Here, cybercriminals offer paths into compromised networks via stolen credentials or direct access. These programs–often ransomware, DDoS attacks or phishing attempts–can be purchased for a monthly fee and given to users in exchange for their personal data.

Malware-as-a-service has been around for years, but is becoming more and more popular with malicious developers. Here, they can create various new malware types and sell them with subscription options that include access to an infected machine.

Though it may be difficult to pinpoint the origins of Packer-as-a-Service, it has been sold to Russian cybercriminals recently. This could be due to an uptick in attacks by an unknown threat actor that exploited a zero-day Windows MSHTML flaw to target businesses.

ESET’s report Operation StealthyTrident indicates the cybercriminal group behind SILKLOADER is affiliated with other threat actors that also target corporate software and servers. They appear to have been expanding their operations recently, as they have begun recruiting more affiliates through spam advertisements.

In a blog post, the group revealed they have been targeting small law firms, freight and logistics businesses throughout North America, Europe and Asia. They claim to have stolen valuable information including financial records.

As of June, they have infected 1 million systems across 17 countries and demanded 70 million bitcoins to decrypt victims’ files and grant them access.

The attackers allegedly laundered the proceeds of these ransomware attacks using a network-based tool known as the Remote Administration Tool, or RAT. This allows hackers to run arbitrary commands on an infected computer.

Another cybergang using the MSHTML bug to launch campaigns is REvil, a Russia-based cybergang which claims to have infected 1 million computers and demanded $70 million in cryptocurrency in order to decrypt victims’ files.

Denis Mihaqlovic Dubnikov, the leader of the Russian mafia, has been extradited to the US for trial on money-laundering charges. This decision was reached following high-level negotiations between Moscow and Washington regarding a prisoner swap to free Americans held in Russia, according to Reuters.

It’s is a Ransomware

A cybercrime group operating from the Commonwealth of Independent States (CIS) is behind ransomware attacks that target victims from former Soviet states. Furthermore, they use cryptocurrency to launder funds earned through their cyberattacks.

This gang is believed to be made up of members of Russian state-sponsored APTs who moonlight as cybercriminals to make money off extorting money from their targets. They reportedly hide their identities behind pseudonyms and alter the names of malware strains they release in an effort to confuse Western law enforcement agencies.

Security experts believe Russian gangs have used ransomware as a tactic to divert attention away from more covert and dangerous state-sponsored cyberattacks. It’s not uncommon for these groups to target multiple targets simultaneously, including businesses and governments alike.

Reports indicate these criminals can exploit software flaws in popular programs like Adobe Reader and Internet Explorer to gain access to a victim’s computer without human intervention – an act known as an exploit pack.

Russian hackers are selling exploit packs in a market that mimics the legitimate software industry. This market sells user-friendly hacking software that can take control of a victim’s PC within seconds. In one year alone, sales of exploit packs have reached over $1 million with vendors providing trial periods, regular updates and 24-hour technical support.

Though some exploit packs can be purchased online, others are sold on the dark web. These markets tend to be controlled by Russian cyber-criminals.

One of Russia’s most notorious gangs, REvil has been responsible for several high-profile attacks against businesses. In addition to its attacks against Quanta Computer and Sol Oriens, REvil was also involved in a supply chain attack against Kaseya – an important player in cyber-security.

The Russian-based group managed to encrypt more than 1 million systems and demand $50 million in ransom from their victims – making this the biggest ransomware attack in recent history.

The Biden administration has repeatedly declared the cyber-crime gangs operating from the CIS as some of the world’s most hazardous, but Russia has yet to act upon these warnings. When asked whether there are plans or even awareness of these groups, Russia largely avoids responding.

Work with Propelex

Ready to build AI
into your stack?

Propelex helps teams evaluate, integrate, and scale AI workflows — from MCP strategy to full agentic architecture. Let's find the right entry point for your organization.