216.73.217.22

Pronsis Loader: A JPHP-Driven Malware Diverging from D3F@ck Loader

· Published 04/12/2024 23:12 · Modified 05/12/2024 10:25

Export JSON

Essential information

Published
04/12/2024 23:12
Modified
05/12/2024 10:25
Tags
2024-12-04 d3f@ck loader jphp latrodectus lumma stealer pronsis loader
Related entities
11 techniques (mitre), 5 malware

Description

A new malware called has been discovered, with similarities to . Both use -compiled executables, but Pronsis uses NSIS for installation instead of Inno Setup. typically delivers and payloads. It employs defense evasion techniques like excluding user directories from Windows Defender scans. The malware establishes persistence through scheduled tasks. Infrastructure analysis revealed multiple IP addresses and open directories used to host malicious files, particularly variants. This discovery highlights the evolving nature of malware threats and the need for continued vigilance in cybersecurity practices.

External references