Sauron Loader (DCSO CyTec): ClickFix/vishing → DLL side-load (rnpkeys) loader sold to RU-speaking buyers — Germany incidents
DCSO CyTec (Medium, 24 September 2026) documents Sauron Loader, a previously undocumented Windows loader seen as the final stage in multiple recent German customer engagements. Delivery chains used ClickFix-style lures and voice phishing (spam flood then fake IT-support callback). An analyzed MSI (SHA-256 ee727d639eaa4ee2e0d7cafbe496e14aaac8df0955d9fb599f2c11dfa1d0f8f2) side-loads via legitimate rnpkeys.exe loading malicious rnp.dll / tdwp.dll, decrypts the loader in memory, persists with a keyroll scheduled task, and talks C2 over encrypted HTTPS with changing paths (Salsa20 + RSA per research). Capabilities: host fingerprint, download/execute varied payloads (EXE/DLL/MSI/scripts), screenshot exfil. Underground alias S4ur0n advertised the loader to Russian-speaking buyers with claimed restrictions on public-sector / post-Soviet targets — not proof of operator attribution for the German cases. IoCs and tooling on DCSO GitHub (Blog_CyTec). Primary: DCSO CyTec Medium; GitHub companion artifacts.
- Product
- Sauron Loader (Windows malware loader; MSI + rnpkeys.exe DLL side-load)
- Versions
- n/a (malware family; analyzed MSI SHA-256 ee727d639eaa4ee2e0d7cafbe496e14aaac8df0955d9fb599f2c11dfa1d0f8f2)
- Exploited in Australia?
- unknown
- Patch to
- No vendor patch — detect and block. Hunt: unexpected rnpkeys.exe loading adjacent rnp.dll/tdwp.dll; keyroll scheduled task; ClickFix/vishing IT-support callbacks after spam floods; MSI installs from untrusted mail; DCSO GitHub YARA/IoCs. User awareness on fake IT remote-assistance and ClickFix paste prompts.
Primary: DCSO CyTec — Sauron Loader: A New Loader Lurking in Underground Forums (24 Sep 2026) · Vendor: DCSO Blog_CyTec GitHub — IoCs / detection tooling for Sauron Loader · Cyber Security News — Sauron Loader DLL side-load / in-memory decrypt summary (25 Sep 2026)
