LOADLOOP: Loader in UAC-0145 Campaign
LOADLOOP is a loader used alongside FLUIDLEECH in the UAC-0145 campaign to deliver additional malware payloads.
LOADLOOP is a loader used alongside FLUIDLEECH in the UAC-0145 campaign to deliver additional malware payloads.
TmcLoader is a C++ loader module that contains an encrypted payload called TmcPayload. It was used in the GoSerpent campaign to exfiltrate…
RomulusLoader is a malware loader used by Silver Fox to deliver additional payloads. It is part of the group's expanding arsenal.
SilentRunLoader is a malware loader employed by Silver Fox to deploy remote access trojans and other malicious tools.
CountLoader is a malware family delivered via DOUBLECUP, with Windows and macOS variants. It establishes persistence via scheduled tasks, audits browser extensions…
A heavily obfuscated Node.js loader delivered as jquery.js, executed via node.exe. It establishes encrypted communications with a remote server and retrieves additional…
SHARDLOADER is a malware loader used by Mustang Panda that sideloads a malicious DLL through legitimately signed binaries like Solid PDF Creator…
Miasma is a multi-stage botnet loader identified in compromised AsyncAPI npm packages. It features a tasking framework with 744 modules, supporting six…
easy-day-js is a malicious npm package that cloned the legitimate 'dayjs' date library. Published by user 'sergey2016', it initially appeared clean but…
CastleLoader is a malware loader used by the GrayBravo threat cluster to deliver payloads such as CastleStealer. It has been observed in…