ARS Loader evolution, a new stealer (ZeroEvil) and AirNaine (TA545)
released on 2018-10-08 @ 02:43:29 PM
ARS Loader, also known as ARS VBS Loader, is written in Visual Basic Script and its main purpose is to control an infected machine via different available commands, acting as a remote access trojan (RAT). Its code is based on ASPC, another Visual Basic Script malware, which at the same time seems to be based on SafeLoader. SafeLoader was written in Visual Basic and created in 2014 as a research project by a group of Spanish developers who were sharing knowledge in a forum called indetectables.net.