Intelligence View
Trojan Sold on Hacking Forum Ends up in Locky Ransomware Distribution Chain
A trojan that appeared at the start of the month on Russian underground hacking forums has now been integrated into the spam distribution chains used to deploy…
The trojan, named Quant Loader, is sold to anyone interested and advertised as a new malware dropper that can be used as a first-stage infection, which can later stealthily download more advanced malware.
Quant Loader used to deliver Locky and Pony
According to a report from security firm Forcepoint, the new trojan appeared on September 1 and by September 12, it was already part of spam campaigns.
Currently, the people behind the Locky ransomware (Zepto variant) and the Pony campaigns have apparently purchased it and are now deploying it.
These spam emails come with ZIP files attached, which when decompressed dump a Windows Script File (WSF) on the user's PC.
Running this file downloads Quant Loader, which after getting boo...