logo

CoffeeLoader: A Brew of Stealthy Techniques

ID: d0aa4538-5db3-5733-8cd0-fdefa3c6792f

STIX ID: report--d0aa4538-5db3-5733-8cd0-fdefa3c6792f

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-05-12

Date Updated: 2026-05-01

...
...

This report provides a technical analysis of CoffeeLoader, a sophisticated Windows loader protected by an "Armoury" GPU-based packer. It describes the dropper, stager, and main module, advanced evasion techniques (call-stack spoofing, sleep obfuscation, fibers), persistence via scheduled tasks, the HTTPS RC4-encrypted C2 protocol with certificate pinning, supported remote commands for executing shellcode/PEs/DLLs, and a simple date-seeded DGA; it also contains multiple actionable indicators (filenames, task name, RC4 keys, pinned public key, example request headers) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.