logo

Exposing FakeBat loader: distribution methods and adversary infrastructure

ID: 9c77dea5-8a0d-5f4e-8bf2-e6fc5c035b8d

STIX ID: report--9c77dea5-8a0d-5f4e-8bf2-e6fc5c035b8d

Feed Name: Sekoia.io Blog

Threat Score
75/100

Date Published: 2024-07-02

Date Updated: 2026-04-29

Author: Quentin Bourgue and Sekoia TDR

...
...

**Executive summary:** Sekoia.io TDR documents FakeBat (EugenLoader/PaykLoader) as a widely used loader in 2024, distributed via drive-by downloads through malvertising, compromised WordPress sites serving fake browser updates, and social-engineering targeting communities; the report outlines the MaaS offering, distribution services, detailed C2 infrastructure evolution, numerous IoCs (domains, MSIX and script hashes), and YARA rules to detect the loader and its stages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.