CyberSecurityBoardThreat Intel · CVEs · Products
Malware

SADBRIDGE: Custom Malware Loader Using PoolParty Variant 7

July 6, 2026

SADBRIDGE is a custom malware loader that uses PoolParty Variant 7 to inject shellcode into explorer.exe. It is designed to deploy GOSAR, a Golang-based reimplementation of Quasar RAT, and has been observed in campaigns targeting Chinese-speaking regions.