HochAktivIm Trend
High Risk
75%
Trojan Loader
Initial-stage malware that downloads and executes secondary payloads.
#malware#loader#dropper
Bedrohungsübersicht
Loaders such as Emotet-style droppers and malvertising chains deliver stealers, ransomware, and remote access tools in staged infections.
Angriffsverhalten
- Downloads encrypted second-stage payloads
- Establishes persistence via scheduled tasks
- Disables security tools when possible
Infektionswege
- Macro-enabled documents
- Cracked software bundles
- Drive-by downloads
Symptome & Indikatoren
- New scheduled tasks
- Unexpected outbound connections
- Subsequent infostealer or ransomware deployment
Sofortige Abwehr
- Block command-and-control domains at firewall
- Isolate endpoint on detection
- Collect memory dump for analysis
Entfernungsanleitung
- Full offline scan in recovery environment
- Remove persistence keys and tasks
- Validate system file integrity
Präventionsmethoden
- Disable macros from internet origins
- Block unsigned script execution
- Real-time behavioral analysis
Telemetrie-Indikatoren
- powershell -enc launches
- WMI event subscription creation
- Known loader mutex strings
They are the delivery mechanism for the most damaging follow-on malware including ransomware and APT tooling.