Veletrix Loader is a Windows malware loader linked in the provided content to a China-nexus threat actor, with one mention specifically associating it with Earth Alux APT. The campaign analyzed was reproduced on Windows 10 Professional and used DLL side-loading via Wondershare software. According to the content, the infection chain began with a spearphishing ZIP attachment themed in a telecom company context, delivering a phishing binary alongside a malicious DLL named drstat.dll. Memory analysis showed that drstat.dll was loaded from the same directory as the phishing-delivered executable, while other DLLs present were standard Visual Studio C++ runtime libraries. Most exports in drstat.dll resolved to a dead function returning 0, but the dr_data_stop export contained the malicious logic. That code dynamically loaded kernel32.dll APIs used for shellcode decryption, memory allocation, and execution. Additional analysis of virtual address descriptors identified anomalous committed memory containing shellcode associated with Veletrix Loader. The shellcode used dynamic API resolution via API hashing, referenced user32.dll and ws2_32.dll, and embedded the command-and-control IP address 62.234.24.38. The suspicious process identified in memory had PID 1724 and communicated with 62.234.24.38 over TCP port 9999, which the content states matched a previously identified indicator of compromise. The mapped ATT&CK techniques mentioned in the content include DLL side-loading, dynamic API resolution, process injection, encrypted payloads, ingress tool transfer, and command-and-control over the non-standard TCP port 9999. One mention in the content states the malware was used in attacks against Chinese telecommunications targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access Spearphishing Attachment [T1566.001] The Threat Actor delivers, through Spear Phishing, a ZIP file targeted at the Telecom company context, containing benign software from Wondershare, which, when executed by the user, executes the malicious DLL that was placed by the adversary, executing the DLL Side-Loading technique.
Defense Evasion Dynamic API Resolution [T1027.007] Both the malicious DLL and Shellcode implement this technique to evade static detection of their capabilities.
Defense Evasion Embedded Payloads [T1027.009] Inside the Malicious DLL, it contains an encrypted payload, which is the Veletrix Loader Shellcode.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another loader campaign used for comparison of operational and tactical similarities with this China-nexus activity.
VELETRIX Loader is a malware loader used to deliver additional malicious payloads. It has been linked to a China-nexus threat actor.
A loader delivered via DLL side-loading using legitimate Wondershare software. It uses a malicious drstat.dll, dynamically resolves APIs, decrypts and executes shellcode in memory, communicates with a C2 server at 62.234.24.38 over TCP/9999, and downloads and executes VShell in memory.
VELETRIX Loader is a malware loader associated with the Earth Alux APT group, used in attacks against Chinese telecommunications companies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.