logo

Technical Analysis of TransferLoader

ID: 5fd75414-35ed-5ca4-bd38-887ba62d57ab

STIX ID: report--5fd75414-35ed-5ca4-bd38-887ba62d57ab

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-05-15

Date Updated: 2026-05-01

...
...

TransferLoader is a modular Windows malware loader that decrypts and executes embedded payloads (commonly a downloader, a backdoor loader, and a backdoor) using custom obfuscation, string encryption, and anti-analysis checks. The report details its decryption chain (custom Base32 + AES variations), anti-VM/debug techniques, two obfuscation methods, downloader behavior (HTTPS fetch, custom XOR decryption, decoy PDF), backdoor loader persistence and pipe-based config management, and the backdoor's network protocol (custom checksum, stream cipher, support for HTTP/TCP, and IPFS fallback). Indicators such as registry keys, named pipe name, HTTP headers, hardcoded keys/hashes, and packet structures are provided to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.