LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

Executive Summary

A malspam email targeting a customer’s mail gateway was intercepted. The message pretended to be from a legitimate employee, requesting a price quote for a fiber‑optic system and included an attachment. The analysis focuses on LausivLoader, a malware loader that transfers data between stages.


Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-09-17T15:06:44+00:00 - Category: threat-intel

Original Description: At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.

"If one advances confidently in the direction of his dream, and endeavours to live the life which he had imagines, he will meet with a success unexpected in common hours."

— Henry David Thoreau
Source: SANS Internet Storm Center