sLoad

References:
  • Hello, internal name of this loader is sLoad. Appeared May 1st. Payload is the UK focused Ramnit ( fB1oN5frGqf ) - 2018-05-19 - Twitter - Kafeine sLoad Ramnit TA554
  • sLoad and Ramnit pairing in sustained campaigns against UK and Italy - 2018-10-23 - Proofpoint - Proofpoint Staff TA554 sLoad Ramnit PsiXBot Gootkit Snatch
  • More Reading:

  • Malicious Powershell Targeting UK Bank Customers - 2018-05-18 - SANS ISC - Xavier Mertens TA554 sLoad
  • For the records, sLoad is still dropping Ramnit "fB1oN5frGqf" in Italy. - 2019-11-07 - Twitter - Kafeine sLoad Ramnit TA554