HelloInjector: Loader DLL Sideloaded via ViPNet Update
HelloInjector is a malicious loader DLL that is sideloaded by the ViPNet update binary itcsrvup64.exe. It injects itself into svchost.exe processes and…
HelloInjector is a malicious loader DLL that is sideloaded by the ViPNet update binary itcsrvup64.exe. It injects itself into svchost.exe processes and…
HelloProxy is a hidden proxy and loader used in the HelloNet attack. It loads additional modules from a C2 server and interferes…
XLoader is an information stealer and loader malware that has been distributed using the Cruciferra crypter. It is known for stealing credentials…
Variant.DenoSnoop.Marte.1 is a loader detection name used by Bitdefender in a September 2025 report on a TradingView malvertising campaign. Confiant's July 2026…
BURNYBEAR is a loader used by UAC-0099 to deliver MATCHBOIL.V2. It is executed as RemoteLibUpdater.exe and can exhaust system resources if launched…
MATCHBOIL.V2 is a modified version of the MATCHBOIL malware, a C#-based loader capable of delivering secondary payloads. It was deployed in attacks…
loader was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Cybersecurity researchers have uncovered a large-scale campaign that weaponizes compromised GitHub repositories to target cPanel and WebHost Manager (WHM) instances. The activity…
SmartLoader is a malware family used in the FakeGit campaign to establish persistence on compromised systems and deploy secondary payloads like StealC.…
FLUIDLEECH is a loader used in the UAC-0145 campaign, disguised as software for removing computer viruses to trick users.