logo

Citrix Users Targeted: AresLoader Via GitLab Repo

ID: 38736e4e-31ac-5dae-8585-63b0a2ff05d8

STIX ID: report--38736e4e-31ac-5dae-8585-63b0a2ff05d8

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-10-25

Date Updated: 2026-07-17

...
...

This report analyzes AresLoader, a MaaS loader first observed in 2022 that dynamically resolves APIs, decrypts embedded payloads, and uses APC-based injection to load secondary malware; CRIL observed it distributing LummaStealer and IcedID via a disguised GitLab repository and provides multiple IOCs (hashes, IPs, URLs) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.