LukeAcha.com

SystemShock Loader

SystemShock Loader research, payload staging, obfuscation, infrastructure pivots, and detection engineering.

SystemShock Loader Research

This is an interesting loader that I stumbled across when observing Fake Meeting Applications, such as fake googlemeets, zoom, and teams files.
The fake software all had odd certificate signers, and all were electron apps that appeared benign at first glance, but its the loaded DLLs that are the problem.
The naming of "SystemShock" comes from my observation that each DLL name started with System. These include:

Research Focus

Related Tags

SystemShock LoaderLoaderObfuscationConfig ExtractionIOCsYARA

Blog