Uncovering MintsLoader With Recorded Future Malware Intelligence Hunting
ID: 5482d2cb-c347-5ca4-930c-a7cdcbfa7844
STIX ID: report--5482d2cb-c347-5ca4-930c-a7cdcbfa7844
Feed Name: Recorded Future Blog
Recorded Future’s Insikt Group describes MintsLoader, a multi-stage JavaScript/PowerShell loader used since 2024 in phishing and drive-by "fake update" campaigns to deliver payloads such as GhostWeaver (RAT), StealC (infostealer), and a modified BOINC client; the loader uses heavy obfuscation, AMSI bypass, sandbox/VM evasion, and a DGA-based HTTP C2, and has been observed in operations tied to SocGholish and TAG-124 across industrial, legal, and energy sector targets in Europe and North America.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
