AltoActivoTendencia
High Risk
75%
Trojan Loader
Initial-stage malware that downloads and executes secondary payloads.
#malware#loader#dropper
Resumen de la amenaza
Loaders such as Emotet-style droppers and malvertising chains deliver stealers, ransomware, and remote access tools in staged infections.
Comportamiento del ataque
- Downloads encrypted second-stage payloads
- Establishes persistence via scheduled tasks
- Disables security tools when possible
Métodos de infección
- Macro-enabled documents
- Cracked software bundles
- Drive-by downloads
Síntomas e indicadores
- New scheduled tasks
- Unexpected outbound connections
- Subsequent infostealer or ransomware deployment
Mitigación inmediata
- Block command-and-control domains at firewall
- Isolate endpoint on detection
- Collect memory dump for analysis
Guía de eliminación
- Full offline scan in recovery environment
- Remove persistence keys and tasks
- Validate system file integrity
Métodos de prevención
- Disable macros from internet origins
- Block unsigned script execution
- Real-time behavioral analysis
Indicadores de telemetría
- powershell -enc launches
- WMI event subscription creation
- Known loader mutex strings
They are the delivery mechanism for the most damaging follow-on malware including ransomware and APT tooling.