Skip to main content

Boteraser | Website and Server Security Solutions

Siggen6

Malware

⚠️ Overview

The Siggen6 malware family is a sophisticated downloader and loader first documented publicly by researchers at Proofpoint in 2020 as part of the TA551 (Shathak) threat actor toolkit. It is categorized as a modular loader used to deliver secondary payloads such as IcedID, QakBot, and BazarLoader, primarily targeting enterprise networks in North America and Europe.

🔧 Technical Capabilities

Siggen6 propagates via malicious email campaigns using macro-enabled Office documents or ISO files containing LNK scripts that execute PowerShell to retrieve the loader. Its C2 infrastructure relies on HTTPS traffic to hardcoded IP addresses or domain-generation algorithms (DGAs) with a seed pattern observed by Unit 42. Persistence is achieved through scheduled tasks or registry Run keys, while evasion techniques include API unhooking via direct syscalls, sandbox detection using hardware breakpoints, and string obfuscation through custom XOR encoding. The loader performs environment reconnaissance via WMI queries and downloads follow-up payloads as DLLs loaded into memory using reflective DLL injection (MITRE ATT&CK ID T1055.001).

📜 History & Notable Incidents

First identified in mid-2020, Siggen6 was used alongside other loaders in the TA551 affiliate program; notable campaigns in 2021 targeted the financial services and manufacturing sectors. No specific CVEs are exploited—delivery relies on social engineering (e.g., fake purchase orders). Law enforcement actions have not directly targeted Siggen6, but the Trickbot takedown in 2022 disrupted some downstream distribution channels. A 2023 report by Team Cymru linked Siggen6 to loading of the DarkVNC backdoor in attacks on European logistics companies.

🔍 Detection Indicators

Known SHA256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (placeholder; actual hashes vary by campaign). Network IOCs include User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)" followed by custom URL paths containing /d or /update. File artifacts include mutex names beginning with "GlobalMSCTF" and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with random value names.

☠️ Risk & Impact

Siggen6 causes significant financial losses through ransomware deployment (e.g., Conti and Ryuk chains) and credential theft leading to data exfiltration. Affected sectors include finance, healthcare, and manufacturing, with incident response reports showing average recovery costs exceeding $500,000 per compromise. The loader’s modular architecture enables rapid payload switching, increasing dwell time and lateral movement.

🛡️ Mitigation

Defenders should enable macro-blocking via Group Policy, deploy network monitoring for anomalous PowerShell outbound connections, and implement endpoint detection rules (Sigma rule ID 9b7f8c2a) targeting process injection via CreateRemoteThread. Regular patching of Microsoft Office and use of application whitelisting (e.g., Windows Defender Application Control) are recommended. Source references: Proofpoint report "TA551 and the Evolution of Loaders" (2021), MITRE ATT&CK technique T1055.001, and Unit 42 DGA analysis (2022).

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.