logo

Inside the Rabbit Hole: BunnyLoader 3.0 Unveiled

ID: 940b4e14-33bf-5614-a5ff-5e5b56d3c766

STIX ID: report--940b4e14-33bf-5614-a5ff-5e5b56d3c766

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2024-03-15

Date Updated: 2026-04-28

Author: Amanda Tanner, Anthony Galiette and Jerome Tujague

...
...

Unit 42 analyzes BunnyLoader, a commercially offered loader/stealer (MaaS) that has rapidly evolved to version 3.0 with a modular architecture (stealer, keylogger, clipper, DoS), RC4‑based obfuscated C2 communications, and active campaigns delivering payloads via droppers, PureCrypter, UPX/Themida packing and social engineering; the report includes detailed IoCs (SHA256s, C2 IPs, BotIDs), a YARA rule, and defensive recommendations for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.