ATT&CKSoftwareStarloader

Starloader

S0188

Malware.View on attack.mitre.org

About this malware

Starloader is a loader component that has been observed loading Felismus and associated tools.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

Starloader has masqueraded as legitimate software update packages such as Adobe Acrobat Reader and Intel.

T1140
Deobfuscate/Decode Files or Information

Starloader decrypts and executes shellcode from a file called Stars.jps.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Sowbug Nov 2017 Open source
    Symantec Security Response. (2017, November 7). Sowbug: Cyber espionage group targets South American and Southeast Asian governments. Retrieved November 16, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.