Inside the Rabbit Hole: BunnyLoader 3.0 Unveiled
ID: 940b4e14-33bf-5614-a5ff-5e5b56d3c766
STIX ID: report--940b4e14-33bf-5614-a5ff-5e5b56d3c766
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-03-15
Date Updated: 2026-04-28
Author: Amanda Tanner, Anthony Galiette and Jerome Tujague
Unit 42 analyzes BunnyLoader, a commercially offered loader/stealer (MaaS) that has rapidly evolved to version 3.0 with a modular architecture (stealer, keylogger, clipper, DoS), RC4‑based obfuscated C2 communications, and active campaigns delivering payloads via droppers, PureCrypter, UPX/Themida packing and social engineering; the report includes detailed IoCs (SHA256s, C2 IPs, BotIDs), a YARA rule, and defensive recommendations for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
