logo

Decoding BATLOADER 2.X: Unmasking the Threat of Stealthy Malware Tactics

ID: d042cf38-36d0-5943-94fb-cbb8ef09ad01

STIX ID: report--d042cf38-36d0-5943-94fb-cbb8ef09ad01

Feed Name: Seqrite Blog

Threat Score
70/100

Date Published: 2023-12-18

Date Updated: 2026-04-30

Author: Rumana Siddiqui

...
...

This report analyzes Batloader delivering an AsyncRAT stealer through a cabinet file → obfuscated batch → PowerShell stages that decrypt and drop a .NET payload; it documents deobfuscation steps, AES-encrypted configuration handling, anti-analysis checks, AMSI and ETW bypass via in-memory patching, persistence via Run key or scheduled task, C2 connection behavior (example host jzx100.myddns.me), and provides two file hashes as IOCs. The analysis warns against downloading cracked software and highlights the potential for stealers to enable follow-on ransomware or additional payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.