Loader
Advanced Espionage Tool Adware AI Android APP APPX file ATM Malware Backdoor Banking Bookit Bot BotNet Code-injection CoinMiners Crypt Cryptocurrency Cryptojacking CyberSpy Data Wiper DDoS DEAMON Destructive Malware DNS Backdoor Downloader Driver Droper EDR and AV Killer ELF ENGINE Espionage Exploit Families Fileless FRAMEWORK FUD Engine Go GPT GPU GRU Malware HTML ICS InfoStealer Injector iOS IoT IRC ISS Java JavaScipt JSON Keylogger Killer Kit LINUX Loader Maas MacOS Macro Malware Military Malware Miner Mobil MultiOS nmp OS OSX OT malware P2P virus Password STEALER Pay-per-install (PPI) PoS Malware PowerShell Program PyPI Python QR trojan Ransom Raspberry RAT Roque Rootkit SMS Spy Spyware SQL Malware Stealer SymbOS Tool Trojan TV UEFI bootkit USB Utility VBA Macro VBE VBS VHD malware Virus Vishing toolset VMware ESXi Windows Wipper WM virus Worm Wrapper
| 24.08.26 | WordlistLoader | WordlistLoader Delivering Amatera via ClearFake Campaigns | MALWARE | LOADER |
| 23.08.26 | SynkLoader | SynkLoader: when you throw in everything but the kitchen sink | MALWARE | LOADER |
| 04.08.26 | DOUBLECUP | Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs | MALWARE | LOADER |
| 02.07.26 | Veil#Drop | Veil#Drop: Blogspot-Hosted PowerShell Loader Delivers PureLog Stealer Through XOR-Encoded In-Memory .NET Payloads | MALWARE | LOADER |
| 27.06.26 | StrikeShark | StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader | MALWARE | LOADER |
| 17.06.26 | Potemkin | Someone's Hands Are on Your Keyboard Then Your Whole Network. Courtesy of ClickFix, Potemkin, RMMProject and EtherRAT | MALWARE | Loader |
| 17.06.26 | BabaDeda Loader | What Is the BabaDeda Loader? Analysis of a New ClickFix Malware Campaign | MALWARE | Loader |
| 03.06.26 | Stealthy Loader | A Missing Piece in PlushDaemon: Anatomy of a Stealthy Loader | MALWARE | LOADER |
| 03.06.26 | PixyNetLoader | Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026 | MALWARE | LOADER |
| 14.05.26 | Gamaredon | Gamaredon: Now Downloading via Windows Updates Best Friend “BITS” | MALWARE | LOADER |
| 14.05.26 | GammaLoad | Gamaredon’s infection chain: Spoofed emails, GammaDrop and GammaLoadS | MALWARE | LOADER |
| 22.04.26 | LOTUSLITE | LOTUSLITE: Targeted espionage leveraging geopolitical themes | MALWARE | LOADER |
|
31.03.26 |
DeepLoad Malware Pairs ClickFix Delivery with AI-Generated Evasion |
LOADER |
||
|
24.03.26 |
StoatWaffle, malware used by WaterPlum |
LOADER |
||
|
06.03.26 |
Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw and MeowMeow |
LOADER |
||
|
17.02.26 |
SmartLoader Clones Oura Ring MCP to Deploy Supply Chain Attack |
LOADER |
||
|
15.02.26 |
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries |
LOADER |
||
|
02.02.26 |
GlassWorm Loader Hits Open VSX via Developer Account Compromise |
LOADER |
||
|
17.01.26 |
Planned failure: Gootloader’s malformed ZIP actually works perfectly |
LOADER |
||
|
20.12.25 |
The YouTube Ghost Network is a malware distribution network that uses
compromised accounts to promote |
LOADER |
||
|
20.12.25 |
From Loader to Looter: ACR Stealer Rides on Upgraded CountLoader |
LOADER |
||
|
10.12.25 |
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries |
LOADER |
||
|
17.11.25 |
RONINGLOADER: DragonBreath’s New Path to PPL Abuse |
Loader |
||
|
12.11.25 |
Gootloader Returns: What Goodies Did They Bring? |
Loader |
||
|
11.11.25 |
Lazarus Group targets Aerospace and Defense with new Comebacker variant |
Loader |
||
|
09.11.25 |
In-memory shellcode loader targeting Cisco Adaptive Security Appliance (ASA) devices |
Loader |
||
|
09.11.25 |
Persistent webshell targeting Cisco Adaptive Security Appliance (ASA) devices. |
Loader |
||
|
08.11.25 |
Cracking XLoader with AI: How Generative Models Accelerate Malware Analysis |
Loader |
||
|
01.11.25 |
The SonicWall Capture Labs threat research team has recently been
monitoring new variants of the HijackLoader |
Loader |
||
|
18.10.25 |
Unit 42 researchers have been tracking phishing campaigns that use
PhantomVAI Loader to deliver information-stealing |
Loader |
||
|
26.09.25 |
Persistent webshell targeting Cisco Adaptive Security Appliance (ASA) devices. |
Loader |
||
|
26.09.25 |
In-memory shellcode loader targeting Cisco Adaptive Security Appliance (ASA) devices. |
Loader |
||
|
20.09.25 |
Silent Push has discovered a new malware loader that is strongly
associated with Russian ransomware gangs that we |
LOADER |
||
|
29.08.25 |
Pirates of The Nang Hai: Follow the Artifacts No One Know |
Loader |
||
|
25.07.25 |
Understanding Current CastleLoader Campaigns |
Loader |
||
|
19.07.25 |
Malware Identified in Attacks Exploiting Ivanti Connect Secure Vulnerabilities |
LOADER |
||
|
18.07.25 |
MaaS operation using Emmenhtal and Amadey linked to threats against Ukrainian entities |
Loader |
||
|
02.07.25 |
Zscaler ThreatLabz has identified a new malware loader that we have
named TransferLoader, which has been active |
LOADER |
||
|
27.05.25 |
NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign |
Loader |
||
|
18.05.25 |
Skitnet is a multi-stage malware that uses Rust and Nim to execute a
stealthy reverse shell over DNS, |
Loader |
||
|
06.05.25 |
TerraStealerV2 and TerraLogger: Golden Chickens' New Malware Families Discovered |
Loader |
||
|
02.05.25 |
Uncovering MintsLoader With Recorded Future Malware Intelligence Hunting |
Loader |
||
|
02.04.25 |
Analyzing New HijackLoader Evasion Tactics |
Loader |
||
|
01.04.25 |
The MSC EvilTwin loader represents a novel approach (CVE-25-26633) to
malware deployment by |
Loader |
||
|
28.03.25 |
CoffeeLoader: A Brew of Stealthy Techniques |
Loader |
||
|
08.03.25 |
Inside Zloader’s Latest Trick: DNS Tunneling |
Loader |
||
|
08.03.25 |
(a.k.a Sardonic Backdoor) is a sophisticated toolkit of the Monstrous Mantis |
Loader |
||
|
04.03.25 |
Havoc: SharePoint with Microsoft Graph API turns into FUD C2 |
Loader |
||
|
20.02.25 |
XLoader Executed Through JAR Signing Tool (jarsigner.exe) |
Loader |
||
|
27.01.25 |
MintsLoader: StealC and BOINC Delivery |
Loader |
||
|
14.12.24 |
NodeLoader Exposed: The Node.js Malware Evading Detection |
LOADER |
||
|
06.12.24 |
Unveiling RevC2 and Venom Loader |
LOADER |
||
|
02.12.24 |
SmokeLoader Attack Targets Companies in Taiwan |
LOADER |
||
|
28.11.24 |
Gaming Engines: An Undetected Playground for Malware Loaders |
LOADER |
||
|
19.11.24 |
Babble Babble Babble Babble Babble Babble BabbleLoader |
LOADER |
||
|
18.11.24 |
The Abuse of ITarian RMM by Dolphin Loader |
LOADER |
||
|
11.11.24 |
Bengal cat lovers in Australia get psspsspss’d in Google-driven Gootloader campaign |
LOADER |
||
|
28.10.24 |
Analyzing Latrodectus: The New Face of Malware Loaders |
LOADER |
||
|
05.09.24 |
Spoofed GlobalProtect Used to Deliver Unique WikiLoader Variant |
Loader |
||
|
21.08.24 |
Meet UULoader: An Emerging and Evasive Malicious Installer. |
Loader |
||
|
02.08.24 |
Phishing targeting Polish SMBs continues via ModiLoader |
Loader |
||
|
11.07.24 |
DodgeBox: A deep dive into the updated arsenal of APT41 | Part 1 |
Loader |
||
|
05.07.24 |
GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks |
Loader |
||
|
03.07.24 |
A Brief History of SmokeLoader, Part 2 |
Loader |
||
|
03.07.24 |
A Brief History of SmokeLoader, Part 1 |
Loader |
||
|
03.07.24 |
Exposing FakeBat loader: distribution methods and adversary infrastructure |
Loader |
||
|
20.06.24 |
LevelBlue Labs Discovers Highly Evasive, New Loader Targeting Chinese Organizations |
Loader |
||
|
18.06.24 |
Info Stealing Campaign Uses DLL Sideloading Through Legitimate Cisco Webex’s Binaries for Initial Execution and Defense Evasion |
Loader |
||
|
14.06.24 |
Dissecting SSLoad Malware: A Comprehensive Technical Analysis |
Loader |
||
|
20.05.24 |
The LATRODECTUS loader evolves to deliver ICEDID and other malware |
Loader |
||
|
08.05.24 |
HijackLoader (a.k.a. IDAT Loader) is a malware loader initially spotted
in 23 that is capable of using a variety of |
Loader |
||
|
19.04.24 |
Cyberespionage Group Earth Hundun's Continuous Refinement of Waterbear and Deuterbear |
Loader |
||
|
28.03.24 |
Agent Tesla's New Ride: The Rise of a Novel Loader |
Loader |
||
|
23.03.24 |
APT29 Uses WINELOADER to Target German Political Parties |
Loader |
||
|
22.03.24 |
Stealc is an information stealer advertised by its presumed developer
Plymouth on Russian-speaking underground forums and |
Loader |
||
|
20.03.24 |
Unit 42 Collaborative Research With Ukraine’s Cyber Agency To Uncover the Smoke Loader Backdoor |
Loader |
||
|
17.03.24 |
Inside the Rabbit Hole: BunnyLoader 3.0 Unveiled |
Loader |
||
|
14.03.24 |
Latest DBatLoader Uses Driver Module to Disable AV/EDR Software |
Loader |
||
|
14.03.24 |
First documented in 2018, DarkGate is a commodity loader with features that include the ability to download and execute files to memory, ... |
Loader |
||
|
02.03.24 |
GUloader Unmasked: Decrypting the Threat of Malicious SVG Files |
Loader |
||
|
02.03.24 |
European diplomats targeted by SPIKEDWINE with WINELOADER |
Loader |
||
|
28.02.24 |
Compromised Routers Are Still Leveraged as Malicious Infrastructure to Target Government Organizations in Europe and the Caucasus |
Loader |
||
|
27.02.24 |
Unveiling UAC-0184: The Steganography Saga of the IDAT Loader Delivering Remcos RAT to a Ukraine Entity in Finland |
Loader |
||
|
17.02.24 |
This malware is delivered by an ISO file, with an DLL inside with a
custom loader. Because of the unique user-agent "bumblebee" |
Loader |
||
|
17.02.24 |
CVE-24-21412: Water Hydra Targets Traders With Microsoft Defender SmartScreen Zero-Day |
Loader |
||
|
17.02.24 |
Pikabot is a malware loader that originally emerged in early
23. Over
the past year, ThreatLabz has been tracking the |
Loader |
||
|
08.02.24 |
HijackLoader Expands Techniques to Improve Defense Evasion |
Loader |
||
|
05.02.24 |
This report aims to detail the functioning of a malware used by FIN7 since 2021, named DiceLoader (also known Icebot), .... |
Loader |
||
|
01.02.24 |
KRUSTYLOADER - RUST MALWARE LINKED TO IVANTI CONNECTSECURE COMPROMISES |
Loader |
||
|
10.01.24 |
Introducing Pikabot, an emerging malware family that comprises a downloader/installer, a loader, and a core backdoor component. |
Loader |
||
|
29.12.23 |
Kimsuky Attack Group Abusing Chrome Remote Desktop |
Loader |
||
|
29.12.23 |
According to Rapid7, this is a loader first spotted in July 23. |
Loader |
||
|
29.12.23 |
FakeBat, známý také jako EugenLoader, je nechvalnì známý softwarový nakladaè a distributor, který se dostal do popøedí v oblasti kybernetických hrozeb. |
Loader |
||
|
29.12.23 |
According to PCrisk, BATLOADER is part of the infection chain where it
is used to perform the initial compromise. This malware |
Loader |
||
|
24.12.23 |
IceXLoader is a commercial malware used to download and deploy additional malware on infected machines. |
Loader |
||
|
29.11.23 |
Loader Galore - TaskLoader at the start of a Pay-per-Install Infection Chain |
Loader |
||
|
29.11.23 |
According to sekoia, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads. |
Loader |
||
|
25.11.23 |
Stealthy WailingCrab Malware misuses MQTT Messaging Protocol |
Loader |
||
|
21.11.23 |
According to Rapid7, this is a loader first spotted in July 23. |
Loader |
||
|
11.11.23 |
FakeBat (also known as EugenLoader) is a malicious software loader and dropper that has emerged as a significant player in the world of cyber threats. |
Loader |
||
|
27.10.23 |
Yellow Liderc ships its scripts and delivers IMAPLoader malware |
Loader |
||
|
21.10.23 |
First documented in 2018, DarkGate is a commodity loader with features
that include the ability to download and execute files to memory, a |
Loader |
||
|
16.10.23 |
HijackLoader Targets Hotels: A Technical Analysis |
Loader |
||
|
16.10.23 |
Fake Update Utilizes New IDAT Loader To Execute StealC and Lumma Infostealers |
Loader |
||
|
03.10.23 |
BunnyLoader, the newest Malware-as-a-Service |
Loader |
||
|
14.09.23 |
Malware distributor Storm-0324 facilitates ransomware access |
Loader |
||
|
10.09.23 |
First documented in 2018, DarkGate is a commodity loader with features
that include the ability to download and execute files to memory, a
|
Loader |
||
|
06.09.23 |
Elastic observed this loader coming with valid code signatures, being used to deploy secondary payloads in-memory. |
Loader |
||
|
02.09.23 |
HemiGate is a backdoor used by Earth Estries. Like most of the tools
used by this threat actor, this backdoor is also executed via DLL
|
Loader |
||
|
31.08.23 |
First documented in 2018, DarkGate is a commodity loader with features
that include the ability to download and execute files to memory, |
Loader |
||
|
24.08.23 |
SMOKE LOADER DROPS WHIFFY RECON WI-FI SCANNING AND GEOLOCATION MALWARE |
Loader |
||
|
30.07.23 |
This loader abuses the benign service Notion for data exchange. |
Loader |
||
|
22.07.23 |
This Delphi loader misuses Cloud storage services, such as Google Drive to download the Delphi stager component. |
Loader |
||
|
08.06.23 |
Malware often arrives hand in hand with other malware. |
Loader |
||
|
25.05.23 |
According to Mandiant, POORTRY is a malware written as a driver, signed with a Microsoft Windows Hardware Compatibility Authenticode signature. |
Loader |
||
|
25.05.23 |
Since Iranian threat actors are known to exploit Exchange servers to
deploy additional malware, it is also possible that this driver has |
Loader |
||
|
16.05.23 |
According to sekoia, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads. |
Loader |
||
|
12.05.23 |
The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. |
LOADER |
||
|
17.04.23 |
This loader abuses the benign service Notion for data exchange. |
Loader |
||
|
3.4.23 |
This Delphi loader misuses Cloud storage services, such as Google Drive to download the Delphi stager component. |
Loader |
||