logo

KoiLoader Reloaded: New Variant Uses LNK Abuse, Script Chains, and PowerShell to Deliver Stealer Payload

ID: 07750ae1-adce-5e40-ada9-9efc59f00ab4

STIX ID: report--07750ae1-adce-5e40-ada9-9efc59f00ab4

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2025-04-01

Date Updated: 2026-04-22

Author: do son

...
...

eSentire’s TRU observed a phishing campaign that uses a ZIP attachment containing a deceptive .lnk that executes hidden PowerShell to download JScript payloads which establish persistence, disable AMSI, and load KoiLoader; KoiLoader performs environment checks and UAC bypasses, then fetches PowerShell stages that install KoiStealer (an info-stealer that harvests credentials, cookies, and browser/app data) and communicates with a custom X25519-based HTTP C2 for command polling and payload injection. The report includes IOCs (filenames, domains) and an emulation toolkit for C2 simulation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.