CherryLoader: A New Go-based Loader Discovered in Recent Intrusions
ID: 42235c54-60bd-572e-a8f4-8009be6e0790
STIX ID: report--42235c54-60bd-572e-a8f4-8009be6e0790
Feed Name: Arctic Wolf
Date Published: 2024-01-24
Date Updated: 2026-07-26
Author: Hady Azzam, Christopher Prest, and Steven Campbell
Arctic Wolf Labs details 'CherryLoader', a Go-based modular downloader observed in active intrusions that decrypts and loads publicly available privilege-escalation tools (PrintSpoofer and JuicyPotatoNG) using XOR and AES, employs process ghosting to evade detection, and establishes persistence by creating an admin account, disabling Defender, and enabling RDP; the report includes technical analysis, decryption scripts, and IOCs (IPs and SHA256 hashes) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
