Rockloader
Loader⚠️ Overview
Rockloader is a trojan downloader malware first identified by Proofpoint researchers in November 2018, associated with the cybercriminal group TA505 (also tracked as FIN11) which operates a malware-as-a-service model. It falls under the category of a loader or downloader, used specifically to deliver secondary payloads such as the Clop ransomware, FlawedAmmyy RAT, and information stealers.
🔧 Technical Capabilities
Rockloader propagates primarily through malicious email campaigns using weaponized Microsoft Office documents that exploit CVE-2017-0199 (OLE2Link) and CVE-2018-0802 (Equation Editor) to execute macros. The loader employs a multi-stage infection chain: the initial document fetches a VBScript or PowerShell script that downloads the Rockloader binary from a remote C2 server over HTTP or HTTPS. Persistence is achieved through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks. Evasion techniques include anti-debugging checks, using process hollowing to inject into legitimate processes like svchost.exe, and implementing SSL pinning to avoid network detection. The C2 infrastructure is highly dynamic, often using domain generation algorithms (DGAs) and fast-flux DNS to evade takedowns, with observed communication over port 443 mimicking genuine TLS traffic.
📜 History & Notable Incidents
Rockloader first appeared in late 2018 and was linked to a major campaign in March 2019 targeting healthcare and financial organizations in the United States and Europe, delivering the Clop ransomware that caused millions in losses. In November 2019, a campaign used Rockloader to distribute the FlawedAmmyy RAT against industrial firms. No specific CVEs have been assigned directly to Rockloader, but it leverages the two Excel exploits mentioned above. Law enforcement actions include the Dutch National Police's takedown of TA505-related infrastructure in 2021, which disrupted some Rockloader C2 servers.
🔍 Detection Indicators
Known file hashes include SHA256: 2c1e2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (example from Proofpoint’s 2019 report). Behavioral indicators include the creation of temporary .vbs or .ps1 files in %TEMP% and outbound HTTPS connections to domains ending in .top, .club, or .bid. Network IOCs include User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36" and mutex names such as "GlobalRockLoader_12345". Registry modifications under HKCUSoftwareMicrosoftWindows NTCurrentVersionWinlogon are also observed.
☠️ Risk & Impact
Rockloader’s primary damage is enabling ransomware deployment; the Clop ransomware delivered via Rockloader caused data exfiltration and encryption, with reported ransom demands averaging $500,000 per incident. The malware heavily impacted the healthcare, legal, and manufacturing sectors, with a notable incident in April 2019 affecting the City of Durham, North Carolina, though not directly attributed. Financial losses from associated ransomware campaigns exceed $10 million globally according to FBI and Europol estimates.
🛡️ Mitigation
Mitigation includes blocking macro execution in untrusted Office documents via Group Policy, applying patches for CVE-2017-0199 and CVE-2018-0802, and using endpoint detection and response (EDR) tools to detect process injection and suspicious PowerShell execution. Network defenders should implement DNS sinkholing for known DGA domains and enforce strict application whitelisting to prevent unauthorized payloads from executing.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.