logo

Hello again, FakeBat: popular loader returns after months-long hiatus

ID: de96d676-e0cd-5aed-bdfa-d08fe1fb49ca

STIX ID: report--de96d676-e0cd-5aed-bdfa-d08fe1fb49ca

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-11-08

Date Updated: 2026-04-28

...
...

Malwarebytes observed a malvertising campaign using a spoofed Notion Google ad that delivered the FakeBat loader (aka EugenLoader/PaykLoader), which decrypts and injects a LummaC2 stealer into MSBuild.exe after multi-stage PowerShell execution and AMSI bypass; the report includes detailed TTPs and multiple IOCs (malicious URLs, file hashes, and C2 domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.