VMDetector Loader is a malware loader described as somewhat rare, with a newly observed variant discovered by SonicWall. The reported campaign delivers the loader through phishing emails using a seemingly benign JPG image with the malware embedded in the image's "pixel data." Its observed purpose is to ultimately deploy the Formbook information stealer. Based on the provided content, the confirmed infection vector is phishing email, the delivery mechanism involves weaponized JPG imagery, and the downstream payload is Formbook. No specific threat actor, targeted industry, platform scope, or concrete indicators of compromise are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware loader used to deliver additional malicious payloads, with a new variant recently discovered.
Loader malware that uses steganography in images to deliver payloads such as Formbook stealer via phishing emails.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.