logo

ManticoraLoader: New Tool By AresLoader Developers

ID: b70058e1-54fa-505c-9603-09353f070c6a

STIX ID: report--b70058e1-54fa-505c-9603-09353f070c6a

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2024-10-23

Date Updated: 2026-07-17

...
...

Cyble Research & Intelligence Labs reports the announcement of a new malware-as-a-service called ManticoraLoader, advertised by the DeadXInject/DarkBLUP actors who previously developed AresLoader and AiDLocker. The loader claims wide Windows compatibility, comprehensive device reconnaissance, persistence mechanisms, modular extensibility, and strong obfuscation to evade detection; it is being marketed with a monthly rental fee and limited clients, and the report warns that if the claimed improvements are real this could increase stealthy stealer/botnet infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.