GuLoader, also known as CloudEyE, is a Windows malware loader and downloader widely used to deliver second-stage commodity malware, particularly remote access trojans and information stealers. It has been observed distributing families including Remcos, FormBook, XLoader, AZORult, Agent Tesla, LokiBot, NanoCore, NetWire, Quasar RAT, Vidar, and related payloads. GuLoader has been linked to broad criminal delivery activity and has been used in campaigns associated with operators such as RATicate; reporting has also connected its use to multiple threat clusters including TA505, TA542, and Gorgon Group.
GuLoader is notable for staging encrypted payloads on legitimate cloud and web services, especially platforms such as Google Drive and OneDrive, then retrieving, decrypting, and executing them in memory. Delivery commonly relies on phishing and malspam, including tax-themed, shipping-themed, invoice-themed, COVID-19-themed, and other business-lure campaigns. Observed infection chains include malicious links, macro-enabled Microsoft Word documents, archive attachments, and documents exploiting CVE-2017-11882. Some campaigns have also used GuLoader as an intermediate stage launched from shortcut-driven or script-based phishing chains.
On execution, GuLoader downloads additional malware over HTTP or via abused cloud-hosted storage, decrypts the payload, and launches it through shellcode execution, process injection, or process hollowing-style techniques. It has been observed injecting into suspended donor processes and using section-mapping-based injection and other native API-heavy execution methods to reduce detection. GuLoader also employs anti-analysis and defense-evasion features, including anti-VM, anti-sandbox, anti-debugging, time-based checks, debugger interference, and attempts to remove or bypass user-mode hooks. Some analyses have documented self-deletion from temporary directories after execution.
Persistence has been observed through Windows RunOnce registry autostart. GuLoader has also been reported using discovery-related API activity and service or product enumeration in some samples, likely to support evasion or execution decisions. The malware’s implementation and packaging have evolved over time, including Visual Basic, NSIS, and .NET variants, while preserving its core role as a flexible malware delivery platform. Its combination of cloud-hosted staging, in-memory execution, and anti-analysis tradecraft has made it a persistent component of phishing-driven Windows malware ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These GuLoader exe files get downloaded and saved to the system after the Coronavirus spam document is opened. This happens when macros are enabled by the victim or after successful exploitation of vulnerabilities like CVE-2017-11882 by the threat actors. | In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
Threat Actors (TAs) leveraging a Remote Code Execution (RCE) vulnerability, identified as CVE-2023-38831, to deliver their payload on compromised systems... The aforementioned vulnerability allows the WinRAR application to extract and execute the malicious script when a user tries to open a benign file within the archive. | Moreover, they observed that several other malware families, including GuLoader and Remcos RAT, were also utilizing the same exploit as a means of delivery.
実行ファイルが使用されるケースでは、実行ファイル自体が情報窃取型マルウェア本体である場合と、実行ファイルがGuLoader(別名:CloudEyE)と呼ばれるダウンローダである場合があります。
実行ファイルが使用されるケースでは、実行ファイル自体が情報窃取型マルウェア本体である場合と、実行ファイルがGuLoader(別名:CloudEyE)と呼ばれるダウンローダである場合があります。
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
Initially identified (by researchers at CheckPoint) as Guloader, the new Visual Basic 6-based installer was tied to a publicly-marketed installation builder called CloudEyE.
In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
Earlier this April, the Redmond-based company warned of several phishing campaigns leveraging tax-related themes to deploy malware such as Latrodectus, AHKBot, GuLoader, and BruteRatel C4 (BRc4). The phishing pages, it added, were delivered via RaccoonO365, with one such campaign attributed to an initial access broker called Storm-0249.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
eSentire has observed a substantial increase in malware being delivered through tax-themed phishing emails. Cybercriminals are exploiting the urgency and importance of tax-related communications to trick individuals into opening malicious email links, leading to malware infections.
Use of Malicious Scripts – Executing scripts (e.g., ‘.vbs’, ‘.msi’) to establish persistence.
GuLoader is then launched resulting in the execution of PowerShell commands... In a recently observed incident involving XWorm malware... Upon execution, a PowerShell command was spawned to retrieve the XWorm payload from its Command-and-Control (C2) server.
attempted to lure victims into enabling malicious macros within email attachments... prompted victims to accept macros... Word documents containing malicious macros.
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
This happens when macros are enabled by the victim or after successful exploitation of vulnerabilities like CVE-2017-11882 by the threat actors.
The ZIP archive contains an LNK file, which if interacted with, leads to the deployment of GuLoader.
В данной статье мы рассмотрим более продвинутый подход к инжекту - в его основе лежит вполне легальный механизм проецирования секций памяти "Mapping"...
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
В данной статье мы рассмотрим более продвинутый подход к инжекту - в его основе лежит вполне легальный механизм проецирования секций памяти "Mapping"...
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
It then injects this decrypted payload to the targeted process or creates a child process of itself and overwrites the child process with the decrypted content from the image base 0x400000.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Tiếp theo sử dụng vòng lặp để quét toàn bộ vùng nhớ từ 0x00010000 tới 0x7FFFF000, gọi hàm ZwQueryVirtualMemory kiểm tra access protection của các vùng nhớ này... gặp chuỗi sẽ gọi hàm tính toán hash cho chuỗi đó và so sánh với các hash đã thiết lập trên Stack. | loader còn sử dụng thêm lệnh CPUID để kiểm tra xem chương trình có đang thực thi trong môi trường ảo hóa hay không
Tiếp theo sử dụng vòng lặp để quét toàn bộ vùng nhớ từ 0x00010000 tới 0x7FFFF000, gọi hàm ZwQueryVirtualMemory kiểm tra access protection của các vùng nhớ này... gặp chuỗi sẽ gọi hàm tính toán hash cho chuỗi đó và so sánh với các hash đã thiết lập trên Stack. | loader còn sử dụng thêm lệnh CPUID để kiểm tra xem chương trình có đang thực thi trong môi trường ảo hóa hay không
313 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
124 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a loader observed using section mapping via NtMapViewOfSection with SEC_IMAGE for payload loading.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
A shellcode-based, memory-resident loader/downloader attributed via C2 infrastructure in this campaign. It is described as running entirely in memory and commonly used to drop infostealers such as Lumma and Vidar and remote access tools including Remcos and AgentTesla.
Mentioned as a malware family that uses the resource section to hide payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.