FakeBat is a malware delivery cluster associated with opportunistic campaigns that commonly use malvertising, SEO poisoning, and fake software or browser-update lures to trick users into executing malicious content. It has been observed abusing modern Windows packaging formats, including MSIX installers built with Advanced Installer, to stage execution through embedded PowerShell launched via StartingScriptWrapper.ps1. Reported payloads delivered by FakeBat include information stealers such as RedLine and ArechClient2, as well as GHOSTPULSE. FakeBat has also been linked to less-common use of fake browser update techniques. Operationally, FakeBat functions primarily as an initial-access and malware-distribution threat rather than a single end-stage payload. Its tradecraft includes social-engineering-driven delivery, script-based execution, and use of installer frameworks to evade user suspicion and blend with legitimate software installation workflows. Observed campaigns have affected organizations across multiple industries and sectors and appear opportunistic rather than narrowly targeted. Known aliases include FakeBat and FakeBat (Storm-1113).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Delivering malware through MSIX packages created with Advanced Installer, using PowerShell execution via StartingScriptWrapper.ps1 to deploy stealers and loaders.
A named threat that has used fake browser update techniques, though less commonly.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.