The Sauron Loader has been identified in cyberattacks targeting German organizations, offering intruders an additional means to distribute malware This article explores loader identified cyberattacks. . Unlike previous instances, this tool is typically the last component in a broader deception-based attack chain rather than a newly disclosed software vulnerability.

This approach makes file scans less noticeable. By combining a trusted executable, hidden code, and repeated executions, attackers can exploit this setup to maintain unauthorized access without an obvious standalone malicious program. For defenders, the research suggests monitoring for unusual installer activity, suspicious library loads by legitimate programs, newly created recurring tasks, and unexplained encrypted outbound connections. Verify unexpected helpdesk contact through an established internal channel, particularly after an inbox flood, and do not run commands presented as quick fixes.

Indicators of compromise (IoCs): - SHA-256 ee727d639eaa4ee2e0d7cafbe496e14aaac8df0955d9fb599f2c11dfa1d0f8f2: MSI installer analyzed - SHA-256 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991: Legitimate executable used for side-loading - SHA-256 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8: Malicious loader library - SHA-256 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7: Malicious decryption and persistence library - File name rnpkeys.exe: Legitimate executable placed by the installer - File name rnp.dll: Side-loaded malicious library - File name tdwp.dll: Malicious decryption and persistence library - Directory C:\ProgramData\keyroll: Hardcoded location for extracted files - Scheduled task keyroll: Task that repeatedly launches the loader - C2 URLs: Configured command-and-control endpoints - Note: IP addresses and domains are defanged (e.g., [.]) to prevent accidental resolution or hyperlinking.