Netskope Threat Labs

SLoad

ATP Sandbox Adv. Heuristics

SLoad (a.k.a. Starslord) is a PowerShell based downloader that its operators used to deliver payloads such as Ramnit and remote access trojans to infected systems. It fetched encrypted payloads from remote servers, decoded them, and executed them entirely in memory, leaving little for disk based scanning. Its campaigns targeted organizations in Europe and the Middle East through spam email, and the family's name became a reference point for script based loader tradecraft.

First seen
January 2022
Last seen
September 2026
Sload
Alert Name
Document-Excel.Downloader.SLoad
Document-Excel.Trojan.SLoad
Document-HTML.Downloader.SLoad
Document-Office.Downloader.SLoad
Document-Office.Trojan.SLoad
Document-Word.Downloader.SLoad
Document-Word.Trojan.Sload
Email.Downloader.SLoad
Script-JS.Backdoor.SLoad
Script-JS.Downloader.SLoad