Chinese Threat Actors Use MSI Files to Bypass Windows, VT Detection
ID: 9bf19991-b60a-5a5c-9207-b9de468f1365
STIX ID: report--9bf19991-b60a-5a5c-9207-b9de468f1365
Feed Name: Dark Reading
Threat Score
Chinese-language threat actors are increasingly distributing a stealthy MSI-based loader dubbed UULoader that evades static detection by stripping executable headers and using DLL sideloading; the loader runs decoy installers, registers Defender exclusions via VBScript, and ultimately drops Gh0stRAT and credential-stealing tools like Mimikatz, with a noted uptick in infections across Southeast Asia targeting Chinese- and Korean-speaking users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
