Exposing FakeBat loader: distribution methods and adversary infrastructure
ID: 9c77dea5-8a0d-5f4e-8bf2-e6fc5c035b8d
STIX ID: report--9c77dea5-8a0d-5f4e-8bf2-e6fc5c035b8d
Feed Name: Sekoia.io Blog
Threat Score
**Executive summary:** Sekoia.io TDR documents FakeBat (EugenLoader/PaykLoader) as a widely used loader in 2024, distributed via drive-by downloads through malvertising, compromised WordPress sites serving fake browser updates, and social-engineering targeting communities; the report outlines the MaaS offering, distribution services, detailed C2 infrastructure evolution, numerous IoCs (domains, MSIX and script hashes), and YARA rules to detect the loader and its stages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
