Technical Analysis of RiseLoader
ID: 26c841f9-4cac-5e6d-8e41-e32220e250a4
STIX ID: report--26c841f9-4cac-5e6d-8e41-e32220e250a4
Feed Name: Zscaler Security Research Blog
This report provides a technical analysis of the RiseLoader malware loader, covering its anti-analysis artifacts, mutex-based execution control, registry infection marker, TCP-based custom C2 protocol (including SET_XORKEYS and structured message types), payload download/execution flow, and capability to collect cryptocurrency wallet and browser-extension data; the analysis also highlights similarities with the RisePro protocol and notes potential tracking via a 1x1 PNG resource.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
