Eugenloader

Malware updated 14 days ago (2024-11-11T15:01:07.313Z)
Download STIX
Preview STIX
EugenLoader, also known as FakeBat or PaykLoader, is a malicious software program that has resurfaced after months of absence. It was detected by Microsoft in mid-November 2023 being delivered through search advertisements mimicking popular productivity applications such as Zoom and Notion. The malware was found to be distributed by an access broker known as Storm-1113, which specializes in malware distribution through search advertisements. Storm-1113 used bogus MSIX installers masquerading as Zoom to distribute EugenLoader, which acts as a conduit for various types of stealer malware and remote access trojans. The malware deployment technique has evolved with threat actors using fraudulent Google search ads impersonating Slack to spread either the Atomic Stealer malware or EugenLoader, depending on the operating system. This development was reported by Malwarebytes. Furthermore, the signed MSI installer hosted on rogue websites contains a malicious PowerShell script, a loader known as FakeBat (aka EugenLoader), which serves as a conduit to deploy RedLine Stealer on the compromised host. Another cybercriminal group, Sangria Tempest (also known as FIN7), used EugenLoader in November 2023 to drop its infamous Carbanak malware framework which subsequently deployed the Gracewire implant. Since this group offers malware deployment as a service, EugenLoader has been used to deploy a variety of implants including Gozi, Redline stealer, IcedID, Smoke Loader, NetSupport Manager (also known as NetSupport RAT), Sectop RAT, and Lumma stealer. These findings highlight an increase in cybercriminals using paid advertisements to lure users to malicious sites and trick them into downloading various types of malware.
Description last updated: 2024-11-11T14:47:17.113Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Fakebat is a possible alias for Eugenloader. FakeBat, also known as Eugenloader and PaykLoader, is a unique malware loader that has been observed in several malvertising campaigns. The malware is often used to drop follow-up payloads such as Lumma stealer. It was first noticed on July 25, 2024, via a malicious ad for Calendly, a popular online
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.