RedLoader is a custom Windows malware used by the financially motivated threat actor GOLD BLADE, also tracked as RedCurl, Red Wolf, and Earth Kapre. It functions as an early-stage payload in targeted intrusion chains associated with commercial espionage and, in some cases, broader monetization activity. The malware is deployed through carefully crafted recruitment-themed lures, including weaponized resume and cover-letter workflows delivered via phishing and third-party job platforms.
Observed RedLoader delivery chains rely on malicious shortcut files disguised as documents, WebDAV-based retrieval of remotely hosted components, and DLL sideloading through legitimately signed Adobe executables. In documented campaigns, a signed Adobe binary is renamed and used to load a malicious DLL as RedLoader stage 1, after which the malware establishes persistence via a scheduled task, retrieves a second-stage executable, and initiates command-and-control communications.
RedLoader is used for host profiling and enterprise reconnaissance. It transmits information about the infected system to attacker-controlled infrastructure and executes PowerShell scripts to collect details about the compromised Active Directory environment. This behavior supports follow-on intrusion activity by enabling GOLD BLADE operators to assess victim environments and prepare subsequent stages. The malware has been linked to campaigns targeting organizations through human-resources and recruiting workflows, with broader reporting connecting the actor’s operations to sectors including services, manufacturing, retail, technology, NGOs, transportation, and other enterprises across multiple countries. RedLoader is notable for its integration into multi-stage tradecraft that combines social engineering, signed-binary abuse, remote component loading, and stealthy execution mechanisms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Related coverage ... GOLD BLADE Unleashes RedLoader with Novel Attack Chain
13 distinct techniques documented for this family, organized by ATT&CK tactic.
RedLoader stage 1 creates a scheduled task named ‘BrowserQE\BrowserQE _<Base64-encoded computer name> ’ on the victim’s system and downloads a standalone executable for stage 2.
Sophos analysts are investigating a new infection chain for the GOLD BLADE cybercriminal group’s custom RedLoader malware, which initiates command and control (C2) communications... RedLoader stage 2 communicates with its C2 server.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related coverage ... GOLD BLADE Unleashes RedLoader with Novel Attack Chain
A custom loader used by GOLD BLADE/RedCurl that is side-loaded via legitimately signed Adobe executables, communicates with C2, and launches PowerShell-based reconnaissance against the victim environment, including Active Directory discovery.
Custom malware used by GOLD BLADE as a multi-stage loader. It is delivered via a malicious LNK file that remotely executes and sideloads a benign executable to load the stage 1 DLL, establishes persistence via a scheduled task, downloads a standalone stage 2 executable, and then initiates C2 communications.
Custom malware used by GOLD BLADE as part of an infection chain. It is delivered via a malicious LNK file, uses remote DLL sideloading with a renamed benign executable, establishes persistence through a scheduled task, downloads a stage 2 executable, and then communicates with its C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.