logo

Babble Babble Babble Babble Babble Babble BabbleLoader

ID: 56718d39-f109-5571-bf08-58b1baa0a136

STIX ID: report--56718d39-f109-5571-bf08-58b1baa0a136

Feed Name: Intezer Blog

Threat Score
75/100

Date Published: 2024-11-17

Date Updated: 2026-04-28

Author: Ryan Robinson

...
...

BabbleLoader is an advanced, highly evasive loader/crypter used to deliver in-memory stealer payloads (notably WhiteSnake and sometimes Meduza). The loader employs heavy junk-code metamorphism, dynamic API hashing/resolution, DirectX and VDLL anti-emulation checks, unique-process-count sandbox heuristics, and a Donut-based unpacking chain to evade static, dynamic, and AI-driven defenses; the report provides technical analysis, observed campaign lures, defensive considerations, and numerous file-hash IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.