Analysis of New Trojan Reveals That it Might Not be so New

Quant Loader, the Trojan that appeared last month on Russian Underground forums has now been integrated into spam distribution chains that are used to deploy Locky ransomware as well as Pony infostealer.

The virus is being sold openly to anyone, and is being advertised as a malware dropper that can be used in the first stage infection, which is a stealthy download of more advanced malware.

Reports state that the new Trojan appeared on September 1st. By September 12th it had already been part of spam campaigns. Currently the hacker behind the Locky ransomware and Pony campaigns have purchased it and are now using it. The spam emails, like any other malicious emails, come with zip files attacked, which when downloaded, unleash the sophisticated, malicious code into the victim’s computer.

Related Post

The Russian hacking forum advertisements state that the new Trojan is written from scratch, can download both EXE and DLL files, and raise user privileges without any aggressive techniques. It avoids antivirus detection to optimize malware installs. The Trojan can limit the number of needed downloads, and optionally balance downloads across multiple servers.

Forcepoint did a technical analysis and said the Trojan is not as new as the claims, and the codebases seem to have been reused from Madness DDoS Trojan. In fact, VirusTotal scans labeled Quant Loader as “Pliskal” and “Crugup”, also terms for the Madness Trojan.  The analysis also revealed that the group was also selling access to the Madness DDoS Trojan that helped build a DDoS stresser service, and the MBS Bitcoin-mining Trojan.

If you liked this article follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin and altcoin price analysis and the latest cryptocurrency news.

reminesjoseph

I am 30 years old. I live in Rural Ohio with my Fiance, and our dog, Bruce.

Share
Published by
reminesjoseph

Recent Posts

Velocity Ticket Debuts As The AI-Powered Invoicing Tool Every Service Business Needs in 2026

Velocity Ticket is trying to fix a major gap in businesses, and the approach it…

2 days ago

Axelar Confirms $4.67M Exploit on Secret Network Bridge, Core Protocol Remains Unaffected

Axelar is moving fast to contain damage after identifying a security incident that has resulted…

3 days ago

Sui Synthetic Dollar suiUSDe Gets Its Own Website

suiUSDe now has a dedicated landing page. The token, officially the eSui Dollar, comes out…

3 days ago

Ventuals Winds Down HIP-3 DEX, vHYPE Withdrawals Now Live For All Holders

Ventuals has fully wound down its HIP-3 DEX, and vHYPE withdrawals are now open. The…

3 days ago

Avalanche Launches Payments Collective With Franklin Templeton And 25 Others

Avalanche has launched the Avalanche Payments Collective, bringing together 28 organizations spanning nearly every layer…

4 days ago

ASTER Whale Reopens 5x Long Days After Getting Fully Liquidated On The Same Token

A wallet tracked as 0x5f91 just opened a fresh 5x leveraged long on ASTER, putting…

4 days ago