CoffeeLoader: A Brew of Stealthy Techniques
ID: d0aa4538-5db3-5733-8cd0-fdefa3c6792f
STIX ID: report--d0aa4538-5db3-5733-8cd0-fdefa3c6792f
Feed Name: Zscaler Security Research Blog
This report provides a technical analysis of CoffeeLoader, a sophisticated Windows loader protected by an "Armoury" GPU-based packer. It describes the dropper, stager, and main module, advanced evasion techniques (call-stack spoofing, sleep obfuscation, fibers), persistence via scheduled tasks, the HTTPS RC4-encrypted C2 protocol with certificate pinning, supported remote commands for executing shellcode/PEs/DLLs, and a simple date-seeded DGA; it also contains multiple actionable indicators (filenames, task name, RC4 keys, pinned public key, example request headers) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
