Skip to content
Sauron

Sauron

Broadcom • September 24, 2026

Security researchers at DCSO recently identified a previously undocumented malware loader dubbed Sauron which has been used to compromise numerous organizations across Germany. Distributed via a Malware-as-a-Service commercial model, the loader serves as the final stage of intrusion chains initiated through social engineering and ClickFix campaigns. Sauron Loader is a C++based utility distributed via malicious MSI packages. Its core purpose is to gather host system telemetry for exfiltration to attacker-controlled command-and-control infrastructure, alongside fetching and executing arbitrary follow-on malware. Upon launch, the binary decrypts an embedded configuration file that guides its operational tasks and payload execution mechanisms across varied formats.

Symantec protects you from this threat, identified by the following:

Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.

Machine Learning-based

Observed domains/IPs are covered under security categories in all WebPulse enabled products

Extracted Entities

Attack Types (1)

Campaigns (1)

Countries (1)

Malware (1)