logo

New TicTacToe Dropper Steals Data, Spreads Multiple Threats on Windows

ID: f96747ef-2dfe-5eee-83b0-a05219c5845b

STIX ID: report--f96747ef-2dfe-5eee-83b0-a05219c5845b

Feed Name: HackRead

Threat Score
75/100

Date Published: 2024-02-15

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

FortiGuard Labs identified a multi-stage Windows malware loader dubbed the TicTacToe dropper that has been active across 2023–2024 and drops multiple final-stage payloads (AgentTesla, LokiBot, Remcos, and others). The dropper uses .iso delivery to evade detection, extracts nested DLL layers at runtime, and employs obfuscation tools (DeepSea, SmartAssembly) and reflective loading; researchers note dynamic string changes and recommend behavior-based EDR for new campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.