Skip to main content
Mallory
MalwareUsed by 1 actor

RedLoader

RedLoader is a custom malware used by the financially motivated GOLD BLADE threat group, also tracked as RedCurl, Red Wolf, and Earth Kapre. It is deployed via DLL side-loading using legitimately signed Adobe executables, including renamed ADNotificationManager.exe, and has been observed in phishing and recruitment-themed intrusion chains. Reported delivery methods include malicious documents disguised as resumes or cover letters, ZIP archives containing LNK files masquerading as PDFs, execution through conhost.exe, and WebDAV-hosted payload retrieval from Cloudflare Workers infrastructure.

RedLoader begins an infection chain by transmitting information about the infected host to a remote command-and-control server and executing PowerShell scripts to gather information about the compromised Active Directory environment. In July 2025 activity documented by Sophos, a stage 1 DLL named netutils.dll was remotely side-loaded, created a scheduled task named BrowserQE\BrowserQE_<Base64-encoded computer name>, downloaded a standalone stage 2 executable from attacker infrastructure, and executed it via PCALua.exe and conhost.exe. The stage 2 payload communicated with C2 and used victim-specific filenames such as BrowserQE_<Base64-encoded computer name>.exe.

The malware has been associated with commercial espionage operations and later hybrid intrusions that also included ransomware deployment by the same actor. Targeting linked to the broader GOLD BLADE/STAC6565 activity has included organizations in Canada, the U.S., Australia, and the U.K., with sectors including services, manufacturing, retail, technology, NGOs, and transportation. High-confidence indicators mentioned in the reporting include the domains automatinghrservices[.]workers[.]dev, quiet[.]msftlivecloudsrv[.]workers[.]dev, and live[.]airemoteplant[.]workers[.]dev; the filename netutils.dll; SHA256 hashes d302836c7df9ce8ac68a06b53263e2c685971781a48ce56b3b5a579c5bba10cc and f5203c7ac07087fd5029d83141982f0a5e78f169cdc4ab9fc097cc0e2981d926; and SHA1 hash 369acb06aac9492df4d174dbd31ebfb1e6e0c5f3.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
RedCurl

Sophos analysts are investigating a new infection chain for the GOLD BLADE cybercriminal group’s custom RedLoader malware, which initiates command and control (C2) communications.

via sophos threat researchsophos.com
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.002Spearphishing LinkEvidence1

The attack starts with a threat actor sending a well-crafted cover letter PDF to a target via a third-party job site such as ‘indeed.com’. A malicious link in the PDF downloads a ZIP archive to the victim’s system.

Execution

3 techniques
T1053.005Scheduled TaskEvidence1

RedLoader stage 1 creates a scheduled task named ‘BrowserQE\BrowserQE _<Base64-encoded computer name> ’ on the victim’s system and downloads a standalone executable for stage 2... The scheduled task uses PCALua.exe and conhost.exe to execute RedLoader stage 2

T1059Command and Scripting InterpreterEvidence1
TacticExecution

The LNK file executes conhost.exe... The scheduled task uses PCALua.exe and conhost.exe to execute RedLoader stage 2

T1059.001PowerShellEvidence1
TacticExecution

RedLoader begins an infection chain that transmits information about the infected host to a remote command and control (C2) host and executes PowerShell scripts that gather information about the compromised Active Directory (AD) environment.

Persistence

2 techniques
T1053.005Scheduled TaskEvidence1

RedLoader stage 1 creates a scheduled task named ‘BrowserQE\BrowserQE _<Base64-encoded computer name> ’ on the victim’s system and downloads a standalone executable for stage 2... The scheduled task uses PCALua.exe and conhost.exe to execute RedLoader stage 2

T1547.009Shortcut ModificationEvidence1

The archive contains a LNK file that masquerades as a PDF. The LNK file executes conhost.exe.

T1053.005Scheduled TaskEvidence1

RedLoader stage 1 creates a scheduled task named ‘BrowserQE\BrowserQE _<Base64-encoded computer name> ’ on the victim’s system and downloads a standalone executable for stage 2... The scheduled task uses PCALua.exe and conhost.exe to execute RedLoader stage 2

T1547.009Shortcut ModificationEvidence1

The archive contains a LNK file that masquerades as a PDF. The LNK file executes conhost.exe.

Discovery

1 technique
T1018Remote System DiscoveryEvidence1
TacticDiscovery

executes PowerShell scripts that gather information about the compromised Active Directory (AD) environment.

Collection

1 technique
T1560Archive Collected DataEvidence1

A malicious link in the PDF downloads a ZIP archive to the victim’s system. The archive contains a LNK file that masquerades as a PDF.

T1071.001Web ProtocolsEvidence1

Sophos analysts are investigating a new infection chain for the GOLD BLADE cybercriminal group’s custom RedLoader malware, which initiates command and control (C2) communications... RedLoader stage 2 communicates with its C2 server.

T1105Ingress Tool TransferEvidence1

This executable leverages WebDAV to contact a CloudFlare domain... A renamed signed version of the Adobe ADNotificationManager.exe executable masquerades as a resume and is remotely hosted on the attacker-controlled server... This file resides in the same directory as the RedLoader stage 1 DLL file (netutils.dll). | RedLoader stage 1 creates a scheduled task... and downloads a standalone executable for stage 2 from ‘live[.]airemoteplant[.]workers[.]dev’.

INDICATORS OF COMPROMISE

IOCs tracked for this family

7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app5 months ago
domain●●●●●●●●●●●●View more in app5 months ago
hash.sha1●●●●●●●●●●●●View more in app5 months ago
domain●●●●●●●●●●●●View more in app5 months ago
domain●●●●●●●●●●●●View more in app5 months ago
hash.sha256●●●●●●●●●●●●View more in app5 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching7

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.