logo

Zloader Analysis

ID: b98770c0-cdfd-588e-9613-a02c163fd49d

STIX ID: report--b98770c0-cdfd-588e-9613-a02c163fd49d

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-09-22

Date Updated: 2026-05-01

...
...

ThreatLabz provides a technical analysis of updated Zloader variants that implement enhanced anti-analysis (runtime API hashing with a changing XOR, junk arithmetic code, filename-based sandbox evasion, and string obfuscation), a modified static config containing a bundled RSA public key, a new DGA producing 32 .com domains per day, and network encryption using 1024-bit RSA + RC4 with the Zeus BinStorage/visual encryption format; the report includes IOCs (expected filenames, botnet IDs such as Bing_Mod5, campaign ID 'M1', and the embedded RSA public key) and notes 15 observed samples likely associated with a single actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.