logo

DBatLoader

ID: 9ec47dff-9be4-5b17-bc0f-868a51d7aad3

STIX ID: report--9ec47dff-9be4-5b17-bc0f-868a51d7aad3

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Technical analysis of DBatLoader/ModiLoader: a Delphi-compiled multi-stage loader that hides an encrypted second-stage payload (stored as a GIF resource) using obfuscation and steganography, decodes it into memory, and executes a second-stage DLL which drops BAT, DLL and EXE artifacts to C:\Users\Public\Libraries. The dropper uses a mock trusted directory UAC bypass with an auto-elevated easinvoker.exe and relative-path DLL hijacking to escalate and run a malicious netutils.dll, modifies Defender exclusions via PowerShell, establishes persistence with a gafiifdX.url autorun entry, and delivers high-impact payloads including Formbook and multiple RAT families.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.