logo

CoffeeLoader Malware Is Stacked With Vicious Evasion Tricks

ID: 5f3b340a-2dd5-5434-ab8e-b79ef4edb5cf

STIX ID: report--5f3b340a-2dd5-5434-ab8e-b79ef4edb5cf

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

CoffeeLoader is a highly evasive Windows malware loader used as a second-stage payload for SmokeLoader to deliver the Rhadamanthys infostealer. Zscaler ThreatLabz documents multiple advanced evasion techniques — including stack spoofing, sleep obfuscation (with optional Windows fibers), and a GPU-based packer dubbed “Armoury” that uses OpenCL — as well as a domain generation algorithm for backup C2 resilience, indicating a clear escalation in attacker sophistication aimed at bypassing EDRs and forensic tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.