logo

BunnyLoader

ID: ccd88c6e-8eb1-5560-b959-3c61d6377cb3

STIX ID: report--ccd88c6e-8eb1-5560-b959-3c61d6377cb3

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

BunnyLoader is a multi-module malware loader/infostealer that establishes persistence via a Run registry value, employs anti-VM and sandbox checks, registers with a C2 (37.139.129.145) using distinct user-agents, and supports modules for credential and wallet theft, clipboard hijacking (clipper), keylogging, downloader (disk and fileless via process hollowing), and remote command execution; stolen data is archived and exfiltrated to the actor's HTTP endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.