logo

FakeBat Loader Malware Spreads Widely Through Drive-by Download Attacks

ID: 0c4354cc-53a4-5677-bf61-249364b76fc2

STIX ID: report--0c4354cc-53a4-5677-bf61-249364b76fc2

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-07-03

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

The report describes widespread distribution of the FakeBat loader-as-a-service (aka EugenLoader/PaykLoader) via drive-by downloads, SEO poisoning, malvertising, compromised websites, and social engineering to deliver numerous secondary payloads (IcedID, RedLine, Ursnif, Lumma, SmokeLoader, etc.). It highlights FakeBat's commercialization and evasion techniques (shift to MSIX and use of valid digital signatures to bypass SmartScreen), links to likely activity clusters (FIN7, Nitrogen, BATLOADER), and related loader campaigns (DBatLoader, Hijack Loader) used to drop info-stealers and RATs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.