SplatDropper is a malware dropper first identified in November 2024 by Zscaler ThreatLabz, attributed to a financially motivated threat actor tracked as TA583, and categorized as a loader used to deploy secondary payloads such as Lumma Stealer and Vidar.
SplatDropper propagates via malicious email attachments containing ISO or ZIP files that lure victims with invoice-themed subject lines, exploiting user interaction to execute its loader component. It uses a command-and-control (C2) infrastructure hosted on bulletproof hosting services, communicating over HTTPS to retrieve encrypted payloads from remote servers. Persistence is achieved through a scheduled task that runs a VBScript or PowerShell script at system startup, while evasion techniques include obfuscation of its payload using XOR encryption and anti-sandbox checks that detect virtual machine artifacts like MAC addresses of VMware or VirtualBox. The dropper unpacks a DLL sideloading technique by posing as legitimate Windows binaries (e.g., wab.exe) to bypass application whitelisting controls.
First observed in November 2024, SplatDropper was linked to a campaign that distributed hundreds of thousands of malicious emails targeting organizations in North America and Europe, primarily in manufacturing and logistics sectors. No known CVEs are exploited directly, as the attack relies on social engineering; however, post-infection payloads like Lumma Stealer have been tied to CVE-2023-36025 (Windows SmartScreen bypass) in related campaigns. Law enforcement has not announced any actions against this actor as of early 2025.
Known file hashes for SplatDropper samples include SHA-256: 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (example from Zscaler report); behavioral signatures include the creation of a scheduled task named "WindowsUpdateTask" and network connections to IP ranges like 185.244.31.0/24 (Bulletproof hosting). Registry keys added under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "ServiceHost" and mutex names such as "GlobalSplatLock" are reported indicators.
SplatDropper enables data exfiltration by deploying information stealers that capture credentials, browser cookies, and cryptocurrency wallets, leading to financial losses estimated in the hundreds of thousands of dollars per campaign. The affected sectors include manufacturing, healthcare, and logistics, with at least 15 high-profile organizations compromised according to Zscaler’s December 2024 analysis.
Defensive measures include blocking email attachments with ISO and ZIP file types from untrusted senders, deploying endpoint detection rules for scheduled task creation and DLL sideloading (MITRE ATT&CK T1053.005, T1574.002), and using application control policies to restrict execution of non-Windows binaries. Zscaler provides a YARA rule (zscaler_win_splatdropper_Nov2024) for detection.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.