#MintsLoader
MintsLoader via PEC: falsi solleciti di pagamento per diffondere malware
cert-agid.gov.it
September 24, 2026 at 8:09 PM
CERT-AGID disrupted a MintsLoader campaign abusing compromised PEC mailboxes to send fake payment reminders, pushing ZIP attachments that launched RATs and stealers. #MintsLoader #PEC #CERTAGID
MintsLoader Via PEC: False Payment Reminders To Spread Malware
CERT-AGID identified and disrupted a new MintsLoader campaign that abused compromised PEC mailboxes to send convincing fake invoice-payment messages to other certified email addresses. The attack chain delivered a ZIP file containing HTML, JavaScript, PowerShell, and MintsLoader components, with rotating infrastructure and DGA-based domains leading to final payloads such as RATs and stealers. #CERT-AGID #MintsLoader #PEC
www.hendryadrian.com
September 25, 2026 at 6:45 AM
New research from Insikt Group on #MintsLoader, often deploying second-stage payloads such as GhostWeaver, StealC, and a modified BOINC client, among others: www.recordedfuture.com/research/unc...
MintsLoader Malware Analysis: Multi-Stage Loader Used by TAG-124 and SocGholish
Discover how MintsLoader operates as a stealthy, obfuscated malware loader distributing GhostWeaver, StealC, and BOINC. Read Recorded Future’s in-depth analysis of its evasion tactics, DGA-based C2s, ...
www.recordedfuture.com
April 29, 2025 at 4:35 PM
🧀 Update on MintsLoader: a thread 🔽
MintsLoader is a JavaScript/PowerShell loader that was first detailed by OCD in 2024.
A new version has been around at least since early-June 2025.
#threatintel #cti #mintsloader
July 3, 2025 at 7:43 AM
-Loads of new infostealers (Pentagon Stealer, Gremlin Stealer, Hannibal Stealer)
-Fog affiliate has a leak
-New MintsLoader malware
-ChoiceJacking attack bypasses juice jacking defenses
-Telegram vuln drama
-Brocade switches, Commvault servers exploited in the wild
-75 0days exploited last year
April 30, 2025 at 9:36 AM
MintsLoader Drops GhostWeaver via Phishing, ClickFix — Uses DGA, TLS for Stealth Attacks thehackernews.com/2025/05/mint...
MintsLoader Drops GhostWeaver via Phishing, ClickFix — Uses DGA, TLS for Stealth Attacks
Stealth malware MintsLoader delivers GhostWeaver RAT + Evades sandboxes using DGA + Powers data theft via encrypted C2
thehackernews.com
May 4, 2025 at 12:48 PM
MintsLoader Malware Uses Sandbox and Virtual Machine Evasion Techniques gbhackers.com/mintsloader-...
MintsLoader Malware Uses Sandbox and Virtual Machine Evasion Techniques
MintsLoader, a malicious loader first observed in 2024, has emerged as a formidable tool in the arsenal of multiple threat actors.
gbhackers.com
May 4, 2025 at 1:27 PM
MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks
MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks
thehackernews.com
January 27, 2025 at 7:52 AM
MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks https://buff.ly/40w6aft
MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks
MintsLoader targets U.S. and European industries in 2025 via PowerShell, fake CAPTCHAs, and advanced evasion.
buff.ly
January 28, 2025 at 8:42 PM
Reposted with correct malware names:

2026-02-02 (Monday) #KongTuke #ClickFix activity leads to #MintsLoader and #GhostWeaver RAT

Today's ClickFix uses the "finger" command, a tactic seen in previous ClickFix activity.

Further details available at www.malware-traffic-analysis.net/2026/02/02/i...
February 3, 2026 at 3:26 AM
Experts shared up-to-date C2 domains and other artifacts related to recent MintsLoader attacks bit.ly/44UmudK
Experts shared up-to-date C2 domains and other artifacts related to recent MintsLoader attacks
MintsLoader is a malware loader delivering the GhostWeaver RAT via a multi-stage chain using obfuscated JavaScript and PowerShell.
buff.ly
May 8, 2025 at 3:12 AM
MintsLoader malware delivers StealC info-stealer and BOINC via spam emails. Targets US/European energy & legal sectors. Uses ClickFix/KongTuke techniques & a DGA for C2 comms. StealC avoids infection in several Eastern European countries.#MintsLoaderMalware
January 27, 2025 at 7:47 AM
New report! Check it out.

This research examines MintsLoader, linked to groups like TAG-124 (LandUpdate808), to deploy capabilities like GhostWeaver and StealC.

Link: www.recordedfuture.com/research/unc...
MintsLoader Malware Analysis: Multi-Stage Loader Used by TAG-124 and SocGholish
Discover how MintsLoader operates as a stealthy, obfuscated malware loader distributing GhostWeaver, StealC, and BOINC. Read Recorded Future’s in-depth analysis of its evasion tactics, DGA-based C2s, ...
www.recordedfuture.com
April 29, 2025 at 3:44 PM
Numerous actors use the technique to deliver Lumma Stealer and other infostealers, RATs such as Xworm and AsyncRAT, loaders including MintsLoader, and remote management tools.
August 6, 2026 at 4:31 PM
TRAC Labs analyses SocGholish/FakeUpdates. The infection chain starts with a fake browser update delivered via compromised websites & a malicious JavaScript file, leading to an obfuscated MintsLoader payload that delivers the GhostWeaver PowerShell backdoor. trac-labs.com/dont-ghost-t...
February 17, 2025 at 10:23 AM
⛪🔎Historically, new MintsLoader JS samples were easy to find because the obfuscation strings consistently used text from a book, Andrew Melville by William Morison.
The associated infrastructure could be tracked thanks to specific patterns and campaign IDs in the C2 URLs: archive.org/details/cu31...
Andrew Melville : Morison, William : Free Download, Borrow, and Streaming : Internet Archive
The metadata below describe the original scanning. Follow the All Files: HTTP link in the View the book box to the left to find XML files that contain more...
archive.org
July 3, 2025 at 7:43 AM
Mistic backdoor hijacks a Microsoft Defender binary to sideload itself, then runs entirely in memory. https://intel.threadlinqs.com/threat/TL-2026-2277 #ThreatIntel #KongTuke #KillSwitch #MintsLoader
September 1, 2026 at 8:12 PM
“New MintsLoader Drops GhostWeaver via Phishing & ClickFix Attack” — CybersecurityNews

#PhishingNews #Phishing
May 2, 2025 at 6:35 PM
MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks Jan 27, 2025Ravie L...

https://blog.kowatek.com/2025/01/27/mintsloader-delivers-stealc-malware-and-boinc-in-targeted-cyber-attacks/

#Security

Event Attributes
January 27, 2025 at 9:51 AM
MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks Jan 27, 2025Ravie L...

https://blog.kowatek.com/2025/01/27/mintsloader-delivers-stealc-malware-and-boinc-in-targeted-cyber-attacks/

#Security

Event Attributes
January 27, 2025 at 7:54 AM