logo

Exposing FakeBat loader: distribution methods and adversary infrastructure

ID: 66975554-441f-5b00-94ff-307bc87f5cbc

STIX ID: report--66975554-441f-5b00-94ff-307bc87f5cbc

Feed Name: Sekoia.com

Threat Score
75/100

Date Published: 2024-07-02

Date Updated: 2026-07-20

...
...

### Executive Summary Sekoia TDR details active FakeBat (EugenLoader/PaykLoader) distribution campaigns in 2023–2024, showing the loader sold as MaaS with a bespoke distribution service and used in large-scale drive-by download operations (malvertising, compromised WordPress fake browser updates, social engineering) to deliver infostealers, loaders, RATs and ransomware; the report includes extensive IoCs (domains, MSIX hashes, PowerShell scripts), observed C2 infrastructure, and YARA rules to aid detection and tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.