216.73.217.22

MintsLoader Malware Analysis: Multi-Stage Loader Used in Cyber Attacks

· Published 29/04/2025 18:01 · Modified 29/04/2025 21:53

Export JSON

Essential information

Published
29/04/2025 18:01
Modified
29/04/2025 21:53
Tags
2025-04-29 asyncrat boinc drive-by-download ghostweaver mintsloader multi-stage loader phishing socgholish stealc tag-124
Related entities
1 intrusion sets (apt), 9 techniques (mitre), 4 malware, 4 others

Description

, a malicious loader first observed in 2024, is employed in and drive-by download campaigns to deploy payloads like , , and modified clients. It uses obfuscated JavaScript and PowerShell scripts in a multi-stage infection chain, featuring sandbox evasion techniques, a domain generation algorithm, and HTTP-based C2 communications. Various threat groups, including and operators, utilize to target industrial, legal, and energy sectors. The loader's sophisticated obfuscation and evasion methods complicate detection, but Recorded Future's Malware Intelligence Hunting provides up-to-date information on new samples and C2 domains.

External references