According to the Sunbelt malware research team, the screensaver spam is pointing to a site put up by Loads.cc website, indicating that the gang, said to be responsible for distribution and installation of numerous spambots, keyloggers, DDoS bots, adware and rootkits, is back in business.
The group behind Loads.cc, believed to be based in Russia, shut down their original domain address in January after suffering suffered a DDoS attack from a rival malware gang utilising a Barracuda botnet, the Sunbelt team said.
After one of the infected screensavers is installed by the recipient, malware activates an HTTP GET request for a PHP script (manda.php), which may return a URL of additional malware for the bot to retrieve and install.
See original article on scmagazineus.com
Personetics Executive Forum 2026 — Sydney
Personetics Executive Forum 2026 — Auckland
Can Testing Keep Up? Quality in the Age of Accelerating Delivery
HPE Networking Day Sydney
iTnews Resilience, Rewired Breakfast



