Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Zloader: Complete Guide

Understand Zloader, how it works, key uses, common issues, and practical considerations. Use this clear guide to make informed decisions.

Table of Contents

This guide provides a clear overview of zloader, including Abuse of Atera. Remote Management Software, Microsoft's Source Code Digital Signature Checking System Has Been Bypassed. Use it to understand the topic, compare the available options, and make a more informed decision.

It is worth noting that the malware is capable of bypassing Microsoft's source code signature checking system. It then deployed malware packages and to date has stolen the personal information of thousands of victims from 111 countries.

Zloader (also known as Terdot or DELoader) is a banking malware first discovered in 2015. It can steal account information and a lot of other private information from infected systems.

Recently, Zloader has also been used to spread other types of malicious code including ransomware such as Ryuk and Egregor.

Zloader guide image 1

Abuse of Atera. Remote Management Software

In the most recent campaign, Zloader infected by distributing the Java.msi file as a modified Atera installer.

Atera is an enterprise remote monitoring and management software widely used in the IT field. As a result, anti-virus tools do not warn victims even if the installer has been modified.

It is not clear how the hacker managed to trick the victim into downloading the malicious file. However, they are more likely to be distributed through crack software or email scams.

Once launched, the malicious code will provide remote access to the system to the hacker. From there, the hacker can execute scripts and upload or download files.

Microsoft's Source Code Digital Signature Checking System Has Been Bypassed

The remarkable thing about this tool is that Microsoft's code signature checking system has been bypassed. Check Point experts confirmed that the appContast.dll file with the Zloader installation and registry modification task contains a valid source code signature. Therefore, the operating system trusts and allows it to execute normally.

Comparing the repaired DLL file with the original Atera DLL, the experts found minor modifications in the checksum and signature size. However, these changes are too small to invalidate the signature but enough to append data to the signature portion of the file.

Microsoft has known about this vulnerability since 2012 and assigned it tracking codes CVE-2020-1599, CVE-2013-3900, and CVE-2021-0151. The company is also trying to release increasingly strict file verification policies. However, for some reason they are still disabled by default.

You can enable strict Microsoft policies by taking the following steps:

  • Open Notepad
  • Copy the following lines of code into Notepad:
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE/Software/Microsoft/Cryptography/Wintrust/Config] "EnableCertPaddingCheck"="1" [HKEY_LOCAL_MACHINE/Software/Wow6432Node/Microsoft/Cryptography/Wintrust/Config] "EnableCertPaddingCheck"="1"
  • Save the Notepad file as a.reg. file
  • Double-click the saved file to run it

As of January 2, 2022, the latest Zloader campaign has hit 2,170 different systems.

Conclusion

Understanding Zloader makes it easier to compare options, avoid common mistakes, and apply the information in this guide more effectively. Review the relevant requirements before making changes or choosing a solution.

FAQ

What is Zloader?

It is worth noting that the malware is capable of bypassing Microsoft's source code signature checking system.

Why is Zloader important?

Understanding Zloader helps you evaluate features, compatibility, performance, and potential limitations before you choose a product or follow a procedure.

What should you consider when using or choosing Zloader?

Consider your specific goal, compatibility requirements, available features, cost, security, and the practical recommendations described in this guide.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.