PathLoader is a Windows PE loader used in the espionage-oriented REF7707 intrusion set, also known as Jewelbug. It retrieves Base64-encoded, AES-encrypted shellcode over HTTPS, decrypts it in memory, changes the memory protection to executable, and runs the payload. PathLoader has been observed delivering the FINALDRAFT backdoor. It uses FNV-based API resolution, SIMD-based string obfuscation, and execution delays to hinder analysis and sandbox detection. REF7707 activity has targeted a South American foreign ministry and has been linked to likely victims in Southeast Asia; identified PathLoader samples date to 2023. The initial-access mechanism used to deploy PathLoader has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Both PATHLOADER and GUIDLOADER are used to download and execute encrypted shellcodes in memory.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Both PATHLOADER and GUIDLOADER are used to download and execute encrypted shellcodes in memory.
“The domains purposely typosquat real known vendors, CheckPoint and Fortinet” and “VMSphere (VMware vSphere).”
Both PATHLOADER and GUIDLOADER are used to download and execute encrypted shellcodes in memory.
"REF7707, a threat campaign involving the FINALDRAFT, PATHLOADER, and GUIDLOADER malware families, provides details about how an espionage-motivated threat evaded defenses using Microsoft’s GraphAPI for C2."
Google's Firebase service, Pastebin, and a Southeast Asian University are third-party services used to host the encrypted payload for the loaders (PATHLOADER and GUIDLOADER) to download and decrypt the last stage of FINALDRAFT.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader referenced as previously used to deploy the FINALDRAFT implant using a payload file named wmsetup.log.
A loader mentioned as having previously deployed FINALDRAFT using a file named wmsetup.log.
Malware family used in the espionage-motivated REF7707 campaign, which evaded defenses using Microsoft GraphAPI for command-and-control.
Loader used in the REF7707 toolkit to install/deploy FinalDraft onto victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.