New CherryLoader Malware Mimics CherryTree to Deploy PrivEsc Exploits
ID: 4a97e094-6f3f-5928-a68a-969e19861f2c
STIX ID: report--4a97e094-6f3f-5928-a68a-969e19861f2c
Feed Name: The Hacker News
Threat Score
**CherryLoader** — Arctic Wolf Labs identified a new Go-based modular loader that masquerades as the CherryTree app, is delivered in a RAR hosted at 141.11.187.70, and unpacks files (cherrytree.exe, NuxtSharp.Data, Spof.Data, Juicy.Data) which it decrypts and executes using process ghosting to load public privilege-escalation tools (PrintSpoofer or JuicyPotatoNG); a post-exploit batch (user.bat) establishes persistence, disables Defender, and alters firewall rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
