Bulwark is a modular malware packer that emerged in 2025 and is marketed on underground forums as a tool to make Windows executables difficult for antivirus and EDR products to detect. Analysis cited in the content describes it as an evasion-focused service rather than a benign software protector, designed to bypass antivirus and delay or evade EDR detection to give attackers more time after execution. Reported capabilities include encryption, polymorphism, runtime decryption, AMSI and ETW bypass, anti-VM and anti-sandbox checks, process injection, anti-analysis features, and persistence. It is described as being delivered through a graphical builder with no coding required and sold as a subscription-based service with tiered modules, lowering the barrier for low-skilled threat actors. The content associates Bulwark with the broader underground malware-as-a-service ecosystem and notes cross-promotion or integration with Aura Stealer, Protection Club, and AV-Lab, with developer updates and support provided via Telegram. Targeting is specifically described for Windows executables. Testing referenced in the content states that Bulwark-packed samples bypassed Microsoft Defender and Bitdefender at launch, were blocked by Avast/AVG, and were allowed to run by SentinelOne before later behavioral detection. High-confidence defensive-relevant indicators from the content are behavioral rather than static, including AMSI/ETW tampering, runtime decryption, process injection, persistence, and delayed suspicious behavior after execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bulwark is a modular malware packer that provides multiple evasion layers (encryption, polymorphism, anti-analysis, persistence) to Windows executables, allowing threat actors to bypass antivirus and EDR detection. It is sold as a service in underground forums and is used to conceal various types of malware payloads, democratizing advanced evasion techniques for low-skill attackers.
Bulwark is a commercial packer and evasion tool designed to bypass antivirus and EDR detection for Windows executables. It provides multiple evasion layers, including encryption, polymorphism, anti-analysis, AMSI/ETW bypass, anti-VM, and persistence, allowing threat actors to conceal malware payloads and delay detection. It is sold as a service in underground forums and is part of a broader malware-as-a-service ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.