216.73.217.22

DBatLoader Distributed via CMD Files

· Published 27/06/2024 09:26 · Modified 27/06/2024 09:56

Export JSON

Essential information

Published
27/06/2024 09:26
Modified
27/06/2024 09:56
Tags
2024-06-27 dbatloader downloader modiloader obfuscation phishing stealthy
Related entities
9 techniques (mitre), 2 malware

Description

A cybersecurity analysis has identified a malicious operation involving the distribution of a , dubbed or , through CMD files disguised as innocuous files. The campaign leverages emails containing compressed CMD files that, when executed on English-language Windows systems, employ and multiple decoding stages to ultimately deploy the malware payload. is a Delphi-compiled executable that loads additional malicious components from external sources, highlighting the persistent threats posed by such distribution tactics.

External references