logo

Warning Against Phishing Emails Distributing GuLoader Malware by Impersonating a Famous International Shipping Company

ID: 78adcde6-5647-5954-9d93-8ef1a8661827

STIX ID: report--78adcde6-5647-5954-9d93-8ef1a8661827

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-03-23

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC observed a phishing campaign impersonating an international shipping company that delivered GuLoader via a malicious attachment; the attachment contains an obfuscated VBScript that executes an embedded PowerShell to download additional files, create a persistence registry key under HKCU\SOFTWARE\[Random Name] (sample: PolySyndetic), and finally inject and execute Xworm RAT via msiexec.exe. The report provides MD5 hashes, download URLs (e.g., https://planachiever.au/admin-admin/Belejrers.fla), and a C2 FQDN (tripplebanks.duckdns.org) as IOCs and warns that GuLoader, as a downloader, may cause secondary infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.