logo

New CherryLoader Malware Mimics CherryTree to Deploy PrivEsc Exploits

ID: 4a97e094-6f3f-5928-a68a-969e19861f2c

STIX ID: report--4a97e094-6f3f-5928-a68a-969e19861f2c

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-01-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**CherryLoader** — Arctic Wolf Labs identified a new Go-based modular loader that masquerades as the CherryTree app, is delivered in a RAR hosted at 141.11.187.70, and unpacks files (cherrytree.exe, NuxtSharp.Data, Spof.Data, Juicy.Data) which it decrypts and executes using process ghosting to load public privilege-escalation tools (PrintSpoofer or JuicyPotatoNG); a post-exploit batch (user.bat) establishes persistence, disables Defender, and alters firewall rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.