'CherryLoader' Malware Allows Serious Privilege Execution
ID: e97740ad-3255-5076-b56c-1a3fa28efaec
STIX ID: report--e97740ad-3255-5076-b56c-1a3fa28efaec
Feed Name: Dark Reading
Researchers observed a threat actor using a Go-based modular loader named CherryLoader (masquerading as legitimate software) in two intrusions to deploy PrintSpoofer and JuicyPotatoNG for privilege escalation. After gaining elevated privileges, the actor executed a batch script that created an admin account, disabled Microsoft Defender components, whitelisted/excluded executables, and modified firewall rules to enable persistence and remote access; CherryLoader’s modular payload-swapping increases operational flexibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
