Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
Brief
Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters.
In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix style fake prompts that tried to make them run harmful instructions.
In other cases, attackers first flooded inboxes with spam, then called while posing as IT support. That sequence created a problem and offered a false solution, making malicious action look like help.
Analysts from DCSO CyTec Blog identified the malware in recent investigations and linked it to an underground sales post.
DCSO said in a report shared with Cyber Security News (CSN) that the tool was advertised to Russian-speaking criminals.
