When analysts at cybersecurity firm Zscaler were combing through their latest findings, they didn’t expect to uncover an entirely new malware strain, let alone one that executes GPU code.
Dubbed CoffeeLoader, the malware was discovered completely by accident. But what it reveals is chilling: threat actors are evolving their tactics by borrowing directly from the red team playbook to slip past traditional defenses.
What is CoffeeLoader?
CoffeeLoader is a family of malware that infects a system by using its GPU to offload parts of its decryption and unpacking routines.
Malware typically executes on the CPU. When security researchers analyze CoffeeLoader in virtual machines (VMs) - the standard practice for safely studying malware - the GPU-dependent code can't execute, making the malware effectively invisible to analysis.
It’s only when you dig deeper that you can find it. Offloading decryption and unpacking routines to the GPU makes it significantly harder for traditional cybersecurity tools to detect.
Brett Stone-Gross, the director of threat intelligence at Zscaler, has seen his fair share of new and terrifying malware, but described CoffeeLoader as a first of its kind, warning that its origin may have come closer than some security analysts might have liked.
“A lot of the techniques that were implemented in CoffeeLoader are known techniques in the red team world,” Stone-Gross told SDxCentral.
“A lot of researchers come up with tactics to defeat security solutions. And this malware author definitely read some of these blog posts as proof of concepts (PoCs) and implemented this in their malware," Stone-Gross added.
The GPU code itself is believed to be lifted from an open source PoC, suggesting the line between research and weaponization is thinner than ever.
What’s more worrying is that the underlying concept behind CoffeeLoader is not that difficult to implement, according to the Zscaler expert.
This new family of malware is particularly nasty. Its GPU-based decryption is enabled by a custom packer, dubbed Armoury, which impersonates legitimate software from Asus – a further sign of just how brazen and technically slick today’s malware authors have become.
The malware has, in some cases, been used to deploy Rhadamanthys – an information-stealing malware designed to swipe credentials and personal data.
Beyond its GPU tricks, CoffeeLoader also uses a grab-bag of anti-analysis techniques, call stack spoofing, sleep obfuscation, and even Windows fibers, to throw security staff off the scent.
And if its command-and-control servers go dark, CoffeeLoader uses a domain generation algorithm to seek new ones, all while encrypting communications with TLS pinning to foil interception.
Detect, dissect, defend
Having unearthed the malware back in March, the team at Zscaler have now implemented a countermeasure in its cloud sandbox.
“Now that we've detected this and we know about it, we've implemented countermeasures in our products. But it’s likely that others may use the same technique but also come up with new ones that would bypass existing measures,” Stone-Gross said.
“One of the things that this case highlights is how many other malware families are out there that implement these novel techniques that are going undetected for some time,” Stone-Gross added.
The CoffeeLoader concept shows the eternal push and pull of the cybersecurity world: Threat actors implement a smarter virus, experts detect it, dissect it, and implement a fix, threat actors improve, and the cycle continues.
Likening that continuous cycle to an arms race, Stone-Gross warned that the concept could be used to create new techniques and continue the symbiotic circle.
While CoffeeLoader’s exact origins remain unclear, its evolutionary path closely echoes SmokeLoader, the infamous backdoor trojan whose hidden payloads were used to steal personal and financial data.
That malware was so prolific, it took an "Avengers"-style team-up of law enforcement agencies and cybersec firms to disrupt it and other ransomwares like Phobos, in what was the largest-ever international action against botnets, with domains seized and more than 100,000 systems cleaned up via uninstall commands.
Stone-Gross suggested there’s “a reasonable chance” that CoffeeLoader is the next evolution of that infamous malware family, with its origins potentially traced back to the one of the minds behind SmokeLoader.
“There was a post at the end of December last year on a criminal forum by the SmokeLoader author that said, ‘I'm creating this new malware,’ and [CoffeeLoader] matches very closely to what they described,” Stone-Gross explained. “There is one bullet point that doesn't align, but everything else kind of matches up. But yeah, so we're keeping an eye on it.”
The origin of the malware is important, given that SmokeLoader was made available as a sort of malware-as-a-service that criminals could pay to essentially rent out customized malware built to attack command-and-control servers.
SmokeLoader stuck around for more than a decade, evolving to become increasingly more nefarious while also far more difficult to detect.
While its origins are uncertain, Stone-Gross reflected on the shift from SmokeLoader to CoffeeLoader and the ongoing battle: “It’s always a cat-and-mouse game, an arms race. Malware authors innovate, and defenders build new detection methods in response.”
A toolkit of stealth
GPU usage, like in CoffeeLoader, is one evasive tactic among many. Stone-Gross points out another novel technique in CoffeeLoader’s toolkit: sleep obfuscation. This means the malware encrypts its code and data during periods of inactivity.
In CoffeeLoader’s case, it only contacts its command-and-control server once every 30 minutes. During the downtime, everything is encrypted in memory, making forensic analysis and memory scanning extremely difficult, since nothing recognizable is visible.
CoffeeLoader also employs a host of sophisticated evasion tricks, like domain generation algorithms to find new servers, TLS certificate pinning to foil interception, and call stack spoofing to confuse endpoint detection and response (EDR) tools that rely on tracking function calls for anomaly detection.
All these features point to one clear truth: CoffeeLoader is a well-crafted, thoughtfully designed malware strain, leveraging the best of both worlds in terms of red team research and criminal countermeasures.
In terms of impact, while CoffeeLoader threatens more consumer-grade hardware, there’s a potential for this to seep through to end-users, such as minicluster users like academics training generative artificial intelligence (genAI) models.
If the lessons learned by the bad actors in improving malware distribution is anything to go by, CoffeeLoader should also have end users a bit worried, considering it integrates infected systems into a botnet, which could lead to distributed attacks on end-user hardware.
And given its detection difficulties, it’ll be hard to identify if it’s even in your system – with SK Telecom’s failure to detect a sizable data breach for around two years a clear sign to keep checking.
Looking forward, cybersec experts may have a new tool up their sleeve to take on those increasingly hard-to-detect malware: AI.
While it comes with a lot of hype, Stone-Gross suggests AI could be part of developing better detection methods for sophisticated malware like CoffeeLoader.
It’s still an evolving field of course, but it could soon become yet another part of the continuous cat-and-mouse game between threat actors and security researchers, which, if CoffeeLoader is anything to go by, shows no signs of slowing.
Comments