logo

The Malware That Chats Back: Inside G DATA’s Real-Time Notepad Encounter with the “Kiss Loader” Author

ID: 94fed05a-ac14-503d-a350-55f0f5ef2ba7

STIX ID: report--94fed05a-ac14-503d-a350-55f0f5ef2ba7

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ddos

...
...

Kiss Loader is a Python-based loader delivered via a deceptive Windows Internet Shortcut that fetches payloads from a TryCloudflare-hosted WebDAV, persists via the Startup folder, decrypts Donut-generated shellcode, and performs Early Bird APC injection into a suspended legitimate process to run payloads (VenomRAT and a .NET utility). The analysis uniquely documented a real-time Notepad conversation with the apparent author, confirming development activity and use of the described techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.