logo

CherryLoader: A New Go-based Loader Discovered in Recent Intrusions

ID: 42235c54-60bd-572e-a8f4-8009be6e0790

STIX ID: report--42235c54-60bd-572e-a8f4-8009be6e0790

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2024-01-24

Date Updated: 2026-07-26

Author: Hady Azzam, Christopher Prest, and Steven Campbell

...
...

Arctic Wolf Labs details 'CherryLoader', a Go-based modular downloader observed in active intrusions that decrypts and loads publicly available privilege-escalation tools (PrintSpoofer and JuicyPotatoNG) using XOR and AES, employs process ghosting to evade detection, and establishes persistence by creating an admin account, disabling Defender, and enabling RDP; the report includes technical analysis, decryption scripts, and IOCs (IPs and SHA256 hashes) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.