#DBatLoader
2025-01-09 (Thursday): #CVE-2017-0199 #XLS --> #HTA --> #VBS --> #steganography --> #DBatLoader or #GuiLoader style malware for #AgentTesla. Data exfil over FTP. A #pcap from an infection, the associated malware, and more info available at www.malware-traffic-analysis.net/2025/01/09/i...
January 11, 2025 at 7:35 AM
#ModiLoader #MalwareAlert #India #ThreatResearch 🚨 AhnLab warns of ModiLoader (DBatLoader) malware exploiting CAB file headers to bypass email security. Delivered via purchase... https://www.hendryadrian.com/warning-against-modiloader-dbatloader-spreading-via-ms-windows-cab-header-batch-file-cmd/
January 17, 2025 at 3:52 AM
Fingers point east.

The Czech Republic has accused Chinese state-backed hackers of attempting to hack into its government network. The US Cybersecurity and Infrastructure Security Agency (CISA) has lost nearly all of its top officials in a recent purge. Google has warned of Viet…

#hackernews #news
Fingers point east.
The Czech Republic has accused Chinese state-backed hackers of attempting to hack into its government network. The US Cybersecurity and Infrastructure Security Agency (CISA) has lost nearly all of its top officials in a recent purge. Google has warned of Vietnam-based hackers using fake AI video generators to spread malware. A new phishing campaign has been discovered that uses DBatLoader to drop the Remcos RAT malware. Hackers have mimicked a popular antivirus website to deliver malware and steal financial data. The real estate firm RE/MAX has allegedly had 150GB of data stolen by the Medusa ransomware, which is demanding a $200,000 ransom. An Iranian national has pleaded guilty to launching a ransomware attack on the city of Baltimore and faces up to 30 years in prison. Cybersecurity experts are warning of the importance of protecting neural data from being exploited. The CyberWire podcast features an interview with Tony Velleca, CEO of CyberProof, discussing exposure management and a more risk-focused approach to prioritize threats. The podcast also invites companies to advertise with them to reach influential leaders and operators in the industry.
thecyberwire.com
May 29, 2025 at 8:07 PM
New Phishing Campaign Uses DBatLoader to Drop Remcos RAT: What Analysts Need to Know

Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.

#hackernews #news
New Phishing Campaign Uses DBatLoader to Drop Remcos RAT: What Analysts Need to Know
Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.
hackread.com
May 29, 2025 at 5:50 AM
How to remove Trojan:Win32/DBatLoader.LKZ!MTB Trojan:Win32/DBatLoader.LKZ!MTB is a sophisticated ...

https://www.bugsfighter.com/remove-trojanwin32-dbatloader-lkzmtb/

#Trojans #Viruses

Event Attributes
How to remove Trojan:Win32/DBatLoader.LKZ!MTB - BugsFighter
Effortlessly remove Trojan:Win32/DBatLoader.LKZ!MTB with our step-by-step guide to restore security.
www.bugsfighter.com
March 30, 2025 at 3:43 PM
DIANNA Explains 3—DBatLoader: Master of Disguise Join DIANNA, the only GenAI assistant designed to explain unknown, never-before-seen threats, in this breakdown of a well-obfuscated attack create...

#Blog

Origin | Interest | Match
August 21, 2025 at 4:48 PM
Hackers Use .PIF Files and UAC Bypass to Drop Remcos Malware on Windows A sophisticated new phishing campaign has emerged, leveraging obsolete Windows file formats and advanced evasion techniques t...

#cyberf="/hashtag/Cyber" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Cyber #security/hashtag/Security" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Security #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Threats #cyber #security #cyber #security #news

Origin | Interest | Match
Hackers Use .PIF Files and UAC Bypass to Drop Remcos Malware on Windows
New phishing campaign uses old Windows formats & DBatLoader to drop Remcos RAT, evading defenses via UAC bypass & LOLBins abuse.
cybersecuritynews.com
June 30, 2025 at 4:39 PM
ModiLoader Malware Attacking Windows Users to Steal Login Credentials A sophisticated malware str...

https://cybersecuritynews.com/modiloader-malware-attacking-windows-users/

#cyberf="/hashtag/Cyber" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Cyber #security/hashtag/Security" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Security #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Threats #cyber #security #news #malware

Result Details
ModiLoader Malware Attacking Windows Users to Steal Login Credentials
ModiLoader (aka DBatLoader) targets Windows users via crafted phishing, posing a major threat to individuals.
cybersecuritynews.com
May 19, 2025 at 9:39 AM
#WormsWeeklyIoC released.
Stats:
1624 #DBatLoader #IoC (2020-2023)
27 active #raccoonv2/#RecordBreaker IoC
450 missing raccoonv2 Indicators added to Threatfox
52 #Amadey #botnet IoC

https://github.com/Gi7w0rm/MalwareConfigLists
https://otx.alienvault.com/user/@Gi7w0rm/pulses
GitHub - Gi7w0rm/MalwareConfigLists: Just some lists of Malware Configs
Just some lists of Malware Configs. Contribute to Gi7w0rm/MalwareConfigLists development by creating an account on GitHub.
github.com
July 27, 2023 at 9:59 PM