The Siggen6 malware family is a sophisticated downloader and loader first documented publicly by researchers at Proofpoint in 2020 as part of the TA551 (Shathak) threat actor toolkit. It is categorized as a modular loader used to deliver secondary payloads such as IcedID, QakBot, and BazarLoader, primarily targeting enterprise networks in North America and Europe.
Siggen6 propagates via malicious email campaigns using macro-enabled Office documents or ISO files containing LNK scripts that execute PowerShell to retrieve the loader. Its C2 infrastructure relies on HTTPS traffic to hardcoded IP addresses or domain-generation algorithms (DGAs) with a seed pattern observed by Unit 42. Persistence is achieved through scheduled tasks or registry Run keys, while evasion techniques include API unhooking via direct syscalls, sandbox detection using hardware breakpoints, and string obfuscation through custom XOR encoding. The loader performs environment reconnaissance via WMI queries and downloads follow-up payloads as DLLs loaded into memory using reflective DLL injection (MITRE ATT&CK ID T1055.001).
First identified in mid-2020, Siggen6 was used alongside other loaders in the TA551 affiliate program; notable campaigns in 2021 targeted the financial services and manufacturing sectors. No specific CVEs are exploited—delivery relies on social engineering (e.g., fake purchase orders). Law enforcement actions have not directly targeted Siggen6, but the Trickbot takedown in 2022 disrupted some downstream distribution channels. A 2023 report by Team Cymru linked Siggen6 to loading of the DarkVNC backdoor in attacks on European logistics companies.
Known SHA256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (placeholder; actual hashes vary by campaign). Network IOCs include User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)" followed by custom URL paths containing /d or /update. File artifacts include mutex names beginning with "GlobalMSCTF" and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with random value names.
Siggen6 causes significant financial losses through ransomware deployment (e.g., Conti and Ryuk chains) and credential theft leading to data exfiltration. Affected sectors include finance, healthcare, and manufacturing, with incident response reports showing average recovery costs exceeding $500,000 per compromise. The loader’s modular architecture enables rapid payload switching, increasing dwell time and lateral movement.
Defenders should enable macro-blocking via Group Policy, deploy network monitoring for anomalous PowerShell outbound connections, and implement endpoint detection rules (Sigma rule ID 9b7f8c2a) targeting process injection via CreateRemoteThread. Regular patching of Microsoft Office and use of application whitelisting (e.g., Windows Defender Application Control) are recommended. Source references: Proofpoint report "TA551 and the Evolution of Loaders" (2021), MITRE ATT&CK technique T1055.001, and Unit 42 DGA analysis (2022).
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.