logo

Chinese Threat Actors Use MSI Files to Bypass Windows, VT Detection

ID: 9bf19991-b60a-5a5c-9207-b9de468f1365

STIX ID: report--9bf19991-b60a-5a5c-9207-b9de468f1365

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-08-22

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

Chinese-language threat actors are increasingly distributing a stealthy MSI-based loader dubbed UULoader that evades static detection by stripping executable headers and using DLL sideloading; the loader runs decoy installers, registers Defender exclusions via VBScript, and ultimately drops Gh0stRAT and credential-stealing tools like Mimikatz, with a noted uptick in infections across Southeast Asia targeting Chinese- and Korean-speaking users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.