logo

WINELOADER Analysis

ID: 3d89d84b-d95b-57bb-9ab8-dba4c39d711b

STIX ID: report--3d89d84b-d95b-57bb-9ab8-dba4c39d711b

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

### Executive summary The report provides a detailed technical analysis of a targeted phishing campaign that distributes the WINELOADER malware via a malicious PDF linking to an HTA; the HTA stages a signed Microsoft executable and a malicious vcruntime DLL for DLL side-loading, after which WINELOADER decrypts modules with a hardcoded RC4 key, performs DLL hollowing, communicates with C2 using encrypted HTTP beacon payloads, and establishes persistence via a scheduled task or registry Run key. The document includes IOCs (URLs, file names, task name), C2 protocol structure, and mitigation-relevant TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.