logo

G-Drive is tapped by a Multistage Malware Downloader

ID: 363ee92e-05a1-5f50-a880-4cef4a421f17

STIX ID: report--363ee92e-05a1-5f50-a880-4cef4a421f17

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive summary:** Zscaler ThreatLabZ analyzed a spam-driven campaign using RTF/XLSM attachments that exploit CVE-2017-8570 to install a highly obfuscated downloader (Win32.Downloader.EdLoader) which employs anti-analysis measures, injects or hollows processes, decrypts XOR-encoded payloads (some hosted on Google Drive), and installs various final payloads including info-stealers and RATs; the report includes technical details and IOCs (hashes) for detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.