CoffeeLoader Malware Is Stacked With Vicious Evasion Tricks
ID: 5f3b340a-2dd5-5434-ab8e-b79ef4edb5cf
STIX ID: report--5f3b340a-2dd5-5434-ab8e-b79ef4edb5cf
Feed Name: Dark Reading
Date Published: 2025-03-31
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
CoffeeLoader is a highly evasive Windows malware loader used as a second-stage payload for SmokeLoader to deliver the Rhadamanthys infostealer. Zscaler ThreatLabz documents multiple advanced evasion techniques — including stack spoofing, sleep obfuscation (with optional Windows fibers), and a GPU-based packer dubbed “Armoury” that uses OpenCL — as well as a domain generation algorithm for backup C2 resilience, indicating a clear escalation in attacker sophistication aimed at bypassing EDRs and forensic tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
