Description
SLoad (a.k.a. Starslord) is a PowerShell based downloader that its operators used to deliver payloads such as Ramnit and remote access trojans to infected systems. It fetched encrypted payloads from remote servers, decoded them, and executed them entirely in memory, leaving little for disk based scanning. Its campaigns targeted organizations in Europe and the Middle East through spam email, and the family's name became a reference point for script based loader tradecraft.
Stats
- First seen
- January 2022
- Last seen
- September 2026
Also known as
Sload
Alert name variants
| Alert Name |
|---|
| Document-Excel.Downloader.SLoad |
| Document-Excel.Trojan.SLoad |
| Document-HTML.Downloader.SLoad |
| Document-Office.Downloader.SLoad |
| Document-Office.Trojan.SLoad |
| Document-Word.Downloader.SLoad |
| Document-Word.Trojan.Sload |
| Email.Downloader.SLoad |
| Script-JS.Backdoor.SLoad |
| Script-JS.Downloader.SLoad |

