New Go-based Malware Loader Discovered I Arctic Wolf
ID: 0ea6f326-849c-5f80-a1e6-923962c01350
STIX ID: report--0ea6f326-849c-5f80-a1e6-923962c01350
Feed Name: Arctic Wolf Blog
CherryLoader is a newly observed Go-based modular loader used in intrusions to deploy encrypted payloads and swap privilege-escalation exploits without recompilation; it uses simple XOR and AES decryption, employs process ghosting for fileless execution, and drops publicly available escalation tools (PrintSpoofer and JuicyPotatoNG) which then run a batch script that creates an administrative account, disables Defender, adds RDP firewall rules, and establishes persistence. The report includes technical analysis, decryption scripts, detailed IOCs (IP and multiple SHA256 hashes), and mitigation/detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
