logo

Hiding in the Cloud: GuLoader Malware Evolves to Evade Detection

ID: 0b710a9b-597c-597d-a550-ee14d068c260

STIX ID: report--0b710a9b-597c-597d-a550-ee14d068c260

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-11

Date Updated: 2026-04-23

Author: Ddos

...
...

Zscaler ThreatLabz provides a technical analysis of GuLoader (CloudEye), highlighting how the malware family has evolved since 2019 to evade defenders by using polymorphic and exception-based control-flow obfuscation, hosting payloads on trusted cloud services (Google Drive, OneDrive), and employing multi-layered XOR decryption using an encrypted binary as a key to retrieve final payloads such as RATs and information stealers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.