MintsLoader Malware Analysis: Multi-Stage Loader Used in Cyber Attacks
Essential information
- Published
- 29/04/2025 18:01
- Modified
- 29/04/2025 21:53
- Tags
- 2025-04-29 asyncrat boinc drive-by-download ghostweaver mintsloader multi-stage loader phishing socgholish stealc tag-124
- Related entities
- 1 intrusion sets (apt), 9 techniques (mitre), 4 malware, 4 others
Description
MintsLoader, a malicious loader first observed in 2024, is employed in phishing and drive-by download campaigns to deploy payloads like GhostWeaver, StealC, and modified BOINC clients. It uses obfuscated JavaScript and PowerShell scripts in a multi-stage infection chain, featuring sandbox evasion techniques, a domain generation algorithm, and HTTP-based C2 communications. Various threat groups, including TAG-124 and SocGholish operators, utilize MintsLoader to target industrial, legal, and energy sectors. The loader's sophisticated obfuscation and evasion methods complicate detection, but Recorded Future's Malware Intelligence Hunting provides up-to-date information on new samples and C2 domains.