logo

Kiss Loader Malware Targets with Early Bird APC Injection in New Attack Campaign

ID: 41b1117e-06e1-597f-9f19-b759bacc0959

STIX ID: report--41b1117e-06e1-597f-9f19-b759bacc0959

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Kiss Loader is a newly discovered, actively developed multi-stage loader that leverages open WebDAV delivered via Cloudflare tunnels to stage encrypted payloads, uses WSH/JScript and Python components to deploy and decrypt payloads (including RAT variants), and achieves stealthy in-memory execution through Donut-generated shellcode and Early Bird APC injection; the analysis documents live operator interaction and provides multiple IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.