logo

'CherryLoader' Malware Allows Serious Privilege Execution

ID: e97740ad-3255-5076-b56c-1a3fa28efaec

STIX ID: report--e97740ad-3255-5076-b56c-1a3fa28efaec

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-01-25

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

Researchers observed a threat actor using a Go-based modular loader named CherryLoader (masquerading as legitimate software) in two intrusions to deploy PrintSpoofer and JuicyPotatoNG for privilege escalation. After gaining elevated privileges, the actor executed a batch script that created an admin account, disabled Microsoft Defender components, whitelisted/excluded executables, and modified firewall rules to enable persistence and remote access; CherryLoader’s modular payload-swapping increases operational flexibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.