New InnoSetup Malware Created Upon Each Download Attempt
ID: 11685821-18f2-5ab0-832e-9edf70bb221f
STIX ID: report--11685821-18f2-5ab0-832e-9edf70bb221f
Feed Name: ASEC
AhnLab ASEC reports a currently active campaign distributing an InnoSetup-based loader dubbed 'InnoLoader' that generates a unique malware sample per download and presents an installer UI; when the user proceeds, the loader queries C2 servers for staged payloads and can install infostealers (StealC), Lu0Bot (UDP-based backdoor/persistent loader), SOCKS5 proxy malware, and other binaries. The actor uses C2 responses and per-download variability to evade analysis and tracking; the report includes hashes, download URLs, FQDNs, and vendor detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
