アクティブトレンド
High Risk
75%

Trojan Loader

Initial-stage malware that downloads and executes secondary payloads.

#malware#loader#dropper

脅威の概要

Loaders such as Emotet-style droppers and malvertising chains deliver stealers, ransomware, and remote access tools in staged infections.

攻撃の挙動

  • Downloads encrypted second-stage payloads
  • Establishes persistence via scheduled tasks
  • Disables security tools when possible

感染経路

  • Macro-enabled documents
  • Cracked software bundles
  • Drive-by downloads

症状と指標

  • New scheduled tasks
  • Unexpected outbound connections
  • Subsequent infostealer or ransomware deployment

即時の緩和策

  • Block command-and-control domains at firewall
  • Isolate endpoint on detection
  • Collect memory dump for analysis

削除ガイド

  • Full offline scan in recovery environment
  • Remove persistence keys and tasks
  • Validate system file integrity

予防方法

  • Disable macros from internet origins
  • Block unsigned script execution
  • Real-time behavioral analysis

テレメトリ指標

  • powershell -enc launches
  • WMI event subscription creation
  • Known loader mutex strings

They are the delivery mechanism for the most damaging follow-on malware including ransomware and APT tooling.

AntiMatter AV — Enterprise Cybersecurity Platform