Water Minyades is a financially motivated cybercrime intrusion set tracked as the operator behind Batloader, an initial-access malware family used to compromise victims and deliver a wide range of follow-on payloads. Activity attributed to the group has been traced to at least 2020. The actor has evolved from earlier use of exploit kits and malware such as SmokeLoader and ZLoader to large-scale social-engineering and malvertising operations centered on fake software downloads, SEO poisoning, malicious advertising, and trojanized installer packages. Water Minyades is known for distributing Batloader through deceptive software-themed lures and installer formats including MSI packages, JavaScript downloaders, and archive-based delivery chains. The group has impersonated numerous legitimate software brands to induce victims to download trojanized installers. Its operations emphasize defense evasion, including oversized installer files, modular scripting, obfuscation, abuse of legitimate packaging frameworks, use of signed or polyglot binaries, and later adoption of PyArmor and PyArmor Pro to protect malicious Python components. Once executed, Batloader performs host and network fingerprinting, including collection of user, host, domain, and local network information, then contacts command-and-control infrastructure to retrieve tailored second-stage payloads. Observed follow-on malware includes Qakbot, Raccoon Stealer, BumbleLoader, Ursnif, Vidar, RedLine Stealer, ZLoader, SmokeLoader, and Cobalt Strike, as well as legitimate remote-management tools such as Atera and Syncro. The actor has also used legitimate utilities and administrative tools to elevate privileges, decrypt payloads, and interfere with security controls. Water Minyades has demonstrated capabilities spanning initial access, reconnaissance, privilege escalation, defense evasion, persistence-enabling post-compromise tooling, and malware delivery for downstream intrusion activity. Batloader infections associated with this actor have been linked to later-stage ransomware operations, including Royal and BlackSuit, making the group a significant access broker and intrusion enabler within the cybercrime ecosystem. Observed victim geography has been concentrated in the United States, with additional activity seen in Canada, Germany, Japan, and the United Kingdom.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates the Batloader initial access malware and uses Pyarmor Pro for script obfuscation, large MSI installers for delivery, UAC elevation, environment/network fingerprinting, and delivery of follow-on malware that can lead to ransomware deployment.
An intrusion set behind the creation and distribution of Batloader, using malvertising, SEO poisoning, fake software download sites, JavaScript/MSI/VHD payloads, and abuse of legitimate tools to deliver follow-on malware and enable ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.