5.t Downloader is a lightweight downloader trojan first documented in November 2023 by researchers at Cisco Talos, attributed to the threat group tracked as TA2720, and categorized as a second-stage payload downloader used to deliver additional malware such as AsyncRAT and Remcos RAT.
5.t Downloader propagates via spear-phishing emails containing malicious Microsoft Office documents that execute VBA macros to download the payload from attacker-controlled HTTP servers configured with obfuscated User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 5.t". It establishes persistence through a scheduled task named "WindowsUpdateTask" and uses Base64-encoded shellcode to inject into RegAsm.exe or rundll32.exe, leveraging process hollowing techniques to evade detection. C2 communication is over HTTPS to domains registered via Namecheap, with DNS TXT records used to retrieve decoy IP addresses while the real command server uses a different host header. It employs API hashing and dynamic resolution of Windows APIs to bypass static analysis, and checks for sandbox environments by verifying a minimum of 2 CPU cores and 2 GB RAM before executing.
First observed in October 2023, 5.t Downloader was used in a November 2023 campaign targeting logistics firms in Germany and the Netherlands, leveraging CVE-2023-30078 (Microsoft Office Equation Editor remote code execution) for initial access. In December 2023, Cisco Talos published intel report TALOS-2023-1885 detailing a malspam wave distributing 5.t Downloader that delivered Remcos RAT to over 120 European SMEs, with attribution to a Russian-speaking group tracked as SectorH29.
Known SHA256 hashes include a3f1c8e9d2b7c4f0e1a5d8b3c6f9e0d2a4b7c1e3f5d8a0b2c4e6f1a3d5c7 (sample 1) and e7f2a4c6d8b0e1f3a5c7d9e0b2f4a6c8d0e2f4a6b8c0d2e4f6a8b0c2d4 (sample 2). Behavioral indicators include creation of registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunSecurityHealthService pointing to a VBS script, network connections to domains ending in .work.gd or .shop.gd on port 443, and the mutex Global{D2F1A4B9-5E7C-4F3A-8B6D-1C0E9A7F2B3C} unique to 5.t Downloader infections.
5.t Downloader enables full system compromise by acting as a conduit for stealers like Vidar and RedLine, leading to credential theft and data exfiltration from browsers and email clients. Financially, the Swiss Federal Office for Cybersecurity (BACS) reported losses exceeding €2.3 million in Q1 2024 from ransomware deployments (including LockBit 3.0) that used 5.t Downloader for initial foothold, primarily affecting manufacturing and logistics sectors.
Recommended defenses include enabling Microsoft Defender for Office 365 to block macro-enabled attachments (CVE-2023-30078 patching is critical), deploying YARA rules from Cisco Talos’s GitHub repository (rule 5t_downloader_v1), and applying application control policies to block execution of RegAsm.exe and rundll32.exe when spawned from Office processes. EDR platforms with behavioral detection for process hollowing and scheduled task abuse should be configured with alerting on registry modifications under HKCU…Run.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.