logo

New Go-based Malware Loader Discovered I Arctic Wolf

ID: 0ea6f326-849c-5f80-a1e6-923962c01350

STIX ID: report--0ea6f326-849c-5f80-a1e6-923962c01350

Feed Name: Arctic Wolf Blog

Threat Score
72/100

Date Published: 2024-01-24

Date Updated: 2026-04-27

...
...

CherryLoader is a newly observed Go-based modular loader used in intrusions to deploy encrypted payloads and swap privilege-escalation exploits without recompilation; it uses simple XOR and AES decryption, employs process ghosting for fileless execution, and drops publicly available escalation tools (PrintSpoofer and JuicyPotatoNG) which then run a batch script that creates an administrative account, disables Defender, adds RDP firewall rules, and establishes persistence. The report includes technical analysis, decryption scripts, detailed IOCs (IP and multiple SHA256 hashes), and mitigation/detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.