logo

GULoader Campaigns: A Deep Dive Analysis of a highly evasive Shellcode based loader

ID: d0df9a27-f60d-5200-8c41-920f044238cd

STIX ID: report--d0df9a27-f60d-5200-8c41-920f044238cd

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2023-05-09

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This report provides a detailed technical analysis of GULoader (GUloader) campaigns: NSIS-based malspam delivery, plugin DLLs that load and decode shellcode, extensive Vectored Exception Handling and runtime padding anti-analysis techniques, process hollowing/code injection into CasPol.exe (or child processes), and final payload retrieval and deobfuscation (commonly deploying stealers like Vidar, Raccoon, and Remcos RAT). The analysis includes resolved API usage, anti-dump and anti-analysis behavior, decoding routines, and a list of observed IOCs (hashes) useful for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.