logo

New InnoSetup Malware Created Upon Each Download Attempt

ID: 11685821-18f2-5ab0-832e-9edf70bb221f

STIX ID: report--11685821-18f2-5ab0-832e-9edf70bb221f

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-06-27

Date Updated: 2026-04-26

Author: KDH

...
...

AhnLab ASEC reports a currently active campaign distributing an InnoSetup-based loader dubbed 'InnoLoader' that generates a unique malware sample per download and presents an installer UI; when the user proceeds, the loader queries C2 servers for staged payloads and can install infostealers (StealC), Lu0Bot (UDP-based backdoor/persistent loader), SOCKS5 proxy malware, and other binaries. The actor uses C2 responses and per-download variability to evade analysis and tracking; the report includes hashes, download URLs, FQDNs, and vendor detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.