26-09-2026
Sauron Loader: A New Loader Lurking in Underground Forums
https://medium.com/@DCSO_CyTec/sauron-loader-a-new-loader-lurking-in-underground-forums-e91fa70db537
Report completeness: High
Actors/Campaigns:
Payouts_king (motivation: cyber_criminal)
0ktapus (motivation: cyber_criminal)
Unc6692 (motivation: cyber_criminal)
Threats:
Sauron
Clickfix_technique
Dll_sideloading_technique
Lockbit
Qilin_ransomware
Clop
Medusa_ransomware
Email_bombing_technique
Blackbasta
Microsoft_quick_assist_tool
Anydesk_tool
Process_injection_technique
Process_hollowing_technique
Victims:
Organizations
Industry:
Government
Geo:
Germany, Russia, Russian
TTPs:
Tactics: 6
Technics: 24
IOCs:
Hash: 4
Path: 1
File: 7
Url: 4
Command: 1
Soft:
Windows Service
Algorithms:
md5, salsa20, zip, exhibit
Functions:
GetFile, TaskResult
Win API:
CreateProcessW, MsiInstallProductW
Languages:
visual_basic, jscript, javascript, powershell
Platforms:
x64
Links:
https://github.com/DCSO/Blog\_CyTec/tree/main/2026\_09\_\_sauron\_loader