CustomerLoader: A new malware distributing a wide variety of payloads
ID: 4c0bbb1c-acf3-53fc-a60c-70523c18d2fc
STIX ID: report--4c0bbb1c-acf3-53fc-a60c-70523c18d2fc
Feed Name: Sekoia.com
Sekoia.io analyzes 'CustomerLoader', a .NET loader (likely offered as a Loader‑as‑a‑Service) that downloads AES‑encrypted dotRunpeX payloads and executes them reflectively to deliver a wide assortment of malware—over 40 families including infostealers, RATs, loaders and commodity ransomware—via phishing, compromised YouTube channels, and fake software pages; the report provides technical analysis (string AES/ECB obfuscation, AMSI bypass, reflective loading), IoCs, infrastructure mapping (C2s and >50 domains), and MITRE ATT&CK mappings to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
