ÉlevéActifTendance
High Risk
75%
Trojan Loader
Initial-stage malware that downloads and executes secondary payloads.
#malware#loader#dropper
Aperçu de la menace
Loaders such as Emotet-style droppers and malvertising chains deliver stealers, ransomware, and remote access tools in staged infections.
Comportement d’attaque
- Downloads encrypted second-stage payloads
- Establishes persistence via scheduled tasks
- Disables security tools when possible
Méthodes d’infection
- Macro-enabled documents
- Cracked software bundles
- Drive-by downloads
Symptômes et indicateurs
- New scheduled tasks
- Unexpected outbound connections
- Subsequent infostealer or ransomware deployment
Atténuation immédiate
- Block command-and-control domains at firewall
- Isolate endpoint on detection
- Collect memory dump for analysis
Guide de suppression
- Full offline scan in recovery environment
- Remove persistence keys and tasks
- Validate system file integrity
Méthodes de prévention
- Disable macros from internet origins
- Block unsigned script execution
- Real-time behavioral analysis
Indicateurs télémétriques
- powershell -enc launches
- WMI event subscription creation
- Known loader mutex strings
They are the delivery mechanism for the most damaging follow-on malware including ransomware and APT tooling.