Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 3 actors

Buer Loader

Buer Loader is a modular malware-as-a-service downloader/loader introduced for sale on underground forums in August 2019. It has been used in phishing and email-based intrusion chains as an initial access malware and has also been observed delivered via malicious Microsoft Excel XLL add-ins. In a documented Ryuk intrusion investigated by Sophos, a targeted phishing email led a victim to a malicious Google Docs-hosted document that executed print_document.exe, identified as Buer Loader; Buer Loader then dropped a Cobalt Strike beacon and additional malware. Sophos and Secureworks reporting cited in the source material associates Buer Loader with ransomware intrusion ecosystems involving Ryuk and Conti/Diavol-linked activity, including GOLD ULRICK/GOLD BLACKBURN overlap, and notes that core GOLD ULRICK operations typically used initial access via TrickBot, BazarLoader, or Buer Loader. Proofpoint also reported TA578 had previously delivered Buer Loader in email campaigns. The content further notes Buer Loader was used in Ryuk attacks where SystemBC was later deployed on domain controllers, and that related campaigns also used BazarLoader or Zloader. High-confidence infection vectors mentioned in the content are phishing emails, malicious documents, and XLL-based delivery. No standalone Buer Loader-specific IOCs are provided in the content beyond the filename print_document.exe observed in one incident.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA578

TA578 has previously been observed in email-based campaigns delivering Ursnif, IcedID, KPOT Stealer, Buer Loader, BazaLoader, and Cobalt Strike.

via proofpoint threat insight blogproofpoint.com
WIZARD SPIDER

Ransomware attacks operated by the core GOLD ULRICK group typically consist of initial access through TrickBot, BazarLoader or Buer Loader.

via secureworks threat profilessecureworks.com
Ryuk actors

"...allowing the document to execute print_document.exe —a malicious executable identified as Buer Loader."

via sophos threat researchnews.sophos.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence2

Proofpoint researchers have observed Bumblebee being distributed in email campaigns by at least three tracked threat actors.

T1566.001Spearphishing AttachmentEvidence1

“Multiple employees… received highly-targeted phishing emails… The link… redirected to a malicious document hosted on docs.google.com… one employee clicked… enabled its content, allowing the document to execute print_document.exe”

Execution

1 technique
T1204User ExecutionEvidence1
TacticExecution

“The user opened the document and enabled its content, allowing the document to execute print_document.exe”

T1105Ingress Tool TransferEvidence1

“Buer Loader malware dropped… a Cobalt Strike ‘beacon,’ along with other malware files… A folder… was dropped on the domain controller… SystemBC… was deployed on the domain controller.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.