216.73.216.233

The Open-Source Builder Behind Malicious Loaders

· Published 08/10/2024 23:17 · Modified 09/10/2024 08:05

Export JSON

Essential information

Published
08/10/2024 23:17
Modified
09/10/2024 08:05
Tags
2024-10-08 blankstealer dc rat lnk files loader builder misteriolnk rat remcos rat
Related entities
3 malware

Description

is a newly discovered open-source that generates LNK, BAT, CMD, and VBS loader files designed to download and execute remote files. Available on GitHub, it poses a significant challenge to security defenses due to minimal detection rates. The tool supports multiple loader methods and obfuscation techniques, making it difficult for traditional security measures to detect. Threat actors have begun using to deploy malware such as , , and . The builder consists of two primary modules: a and an obfuscator, allowing for the creation of various file types with customizable icons and obfuscation capabilities. This versatile toolkit emphasizes flexibility, adaptability, and evasion, making it a potent threat in the cybersecurity landscape.

External references