logo

Uncovering MintsLoader With Recorded Future Malware Intelligence Hunting

ID: 5482d2cb-c347-5ca4-930c-a7cdcbfa7844

STIX ID: report--5482d2cb-c347-5ca4-930c-a7cdcbfa7844

Feed Name: Recorded Future Blog

Threat Score
75/100

Date Published: 2025-04-29

Date Updated: 2026-04-28

...
...

Recorded Future’s Insikt Group describes MintsLoader, a multi-stage JavaScript/PowerShell loader used since 2024 in phishing and drive-by "fake update" campaigns to deliver payloads such as GhostWeaver (RAT), StealC (infostealer), and a modified BOINC client; the loader uses heavy obfuscation, AMSI bypass, sandbox/VM evasion, and a DGA-based HTTP C2, and has been observed in operations tied to SocGholish and TAG-124 across industrial, legal, and energy sector targets in Europe and North America.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.