MISTPEN Downloader: Lightweight Malware Loader
MISTPEN is a lightweight downloader used by Lazarus Group to communicate with C2 servers via Microsoft Graph API and OneDrive. It retrieves…
MISTPEN is a lightweight downloader used by Lazarus Group to communicate with C2 servers via Microsoft Graph API and OneDrive. It retrieves…
WEL1DROPPER is a downloader used in a campaign involving nearly 800 malicious npm packages. It identifies the host OS and architecture, then…
PUBLOAD is a downloader used to distribute secondary tools like FDMTP. It was first highlighted by Trend Micro in September 2024 as…
TookPS is a PowerShell downloader used as the initial payload for OkoBot. It has been active since March 2025, delivered via fake…
PteroPaste is used by Gamaredon to weaponize USB drives and download additional PowerShell payloads via an encrypted channel.