ÉlevéActifTendance
High Risk
75%

Trojan Loader

Initial-stage malware that downloads and executes secondary payloads.

#malware#loader#dropper

Aperçu de la menace

Loaders such as Emotet-style droppers and malvertising chains deliver stealers, ransomware, and remote access tools in staged infections.

Comportement d’attaque

  • Downloads encrypted second-stage payloads
  • Establishes persistence via scheduled tasks
  • Disables security tools when possible

Méthodes d’infection

  • Macro-enabled documents
  • Cracked software bundles
  • Drive-by downloads

Symptômes et indicateurs

  • New scheduled tasks
  • Unexpected outbound connections
  • Subsequent infostealer or ransomware deployment

Atténuation immédiate

  • Block command-and-control domains at firewall
  • Isolate endpoint on detection
  • Collect memory dump for analysis

Guide de suppression

  • Full offline scan in recovery environment
  • Remove persistence keys and tasks
  • Validate system file integrity

Méthodes de prévention

  • Disable macros from internet origins
  • Block unsigned script execution
  • Real-time behavioral analysis

Indicateurs télémétriques

  • powershell -enc launches
  • WMI event subscription creation
  • Known loader mutex strings

They are the delivery mechanism for the most damaging follow-on malware including ransomware and APT tooling.

AntiMatter AV — Enterprise Cybersecurity Platform