216.73.217.22

Technical Analysis of TransferLoader

· Published 15/05/2025 01:56 · Modified 21/05/2025 20:28

Export JSON

Essential information

Published
15/05/2025 01:56
Modified
21/05/2025 20:28
Tags
2025-05-15 anti-analysis backdoor c2 downloader ipfs morpheus obfuscation ransomware transferloader
Related entities
7 observables, 18 techniques (mitre), 2 malware, 2 others

Description

is a newly identified malware loader active since February 2025. It comprises multiple components including a , , and specialized loader. The malware employs various techniques and code to hinder reverse engineering. has been observed delivering . Its module enables execution of arbitrary commands on compromised systems and uses the InterPlanetary File System as a fallback for server updates. The malware utilizes both HTTPS and raw TCP communication methods, with a unique encryption process for network packets. 's consistent use in deploying additional payloads suggests it will continue to be a threat in future attacks.

External references