WastedLoader
Loader⚠️ Overview
WastedLoader is a downloader malware first documented by Cisco Talos in February 2021, believed to be operated by a Russian-speaking threat actor tracked as TA577, primarily used to deliver secondary payloads such as QakBot and Cobalt Strike. It falls under the Loader malware category, specializing in initial access and payload delivery via malicious email campaigns.
🔧 Technical Capabilities
WastedLoader propagates through phishing emails containing password-protected ZIP archives that harbor HTML files using JavaScript or VBScript to retrieve the payload. The malware employs a multi-stage infection chain: the initial script downloads a DLL loader from a compromised website, which then decrypts and executes the final payload in memory. Its command-and-control (C2) infrastructure uses HTTPS with hardcoded IP addresses or domain names, often leveraging compromised legitimate servers. Persistence is achieved via scheduled tasks or registry Run keys, while evasion techniques include disabling Windows Defender via registry modifications, using process hollowing, and checking for sandbox environments by examining disk size and RAM. The loader can also terminate security software processes and download additional modules like information stealers or ransomware.
📜 History & Notable Incidents
First observed in early 2021, WastedLoader was notably used in campaigns targeting healthcare, manufacturing, and legal sectors in the United States and Europe during 2022-2023. A high-profile incident involved delivering the Black Basta ransomware in partnership with the FIN7 group, as reported by Mandiant. No specific CVEs are directly exploited by WastedLoader itself, but it leverages common vulnerabilities in internet-facing applications like Microsoft Exchange (ProxyShell) for initial access in some campaigns.
🔍 Detection Indicators
Behavioral indicators include the creation of scheduled tasks named ‘OneDrive Update’ or ‘WindowsFontCache’ and modifications to the registry key ‘HKCUSoftwareMicrosoftWindowsCurrentVersionRun’. Network IOCs comprise POST requests to unusual URI paths such as ‘/img/upload.php’ or ‘/api/v2/log’ with User-Agent strings mimicking Google Chrome or Mozilla Firefox. Known file hashes include SHA256: 0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1. Mutex names like ‘GlobalWastedLoader_Mutex’ have been observed in memory analysis.
☠️ Risk & Impact
WastedLoader poses a high risk as a gateway for ransomware (e.g., Black Basta, Conti) and banking trojans, leading to data exfiltration, system encryption, and financial losses of up to millions of dollars per incident. The affected sectors include healthcare, legal services, and manufacturing, with significant operational disruption reported.
🛡️ Mitigation
Mitigation strategies include blocking suspicious email attachments with password-protected archives, deploying endpoint detection and response (EDR) tools like Microsoft Defender for Endpoint with behavioral detections, and applying the principle of least privilege. Organizations should monitor for the registry and scheduled task indicators listed above and enforce application control to prevent unauthorized script execution.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.