GUIDLOADER is a malware loader used in the espionage-focused REF7707 intrusion set, also tracked as Jewelbug, CL-STA-0049, and Earth Alux. It retrieves encrypted shellcode from attacker-controlled infrastructure and third-party hosting services, decrypts it, and executes it directly in memory. GUIDLOADER has been observed delivering FINALDRAFT, a modular remote-access backdoor that uses Microsoft Graph API for command-and-control. Samples associated with the family appeared during 2023, including development-stage variants with incomplete decryption logic and debugging artifacts. REF7707 activity has targeted a South American foreign-ministry environment and has been linked to additional activity in Southeast Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Both PATHLOADER and GUIDLOADER are used to download and execute encrypted shellcodes in memory.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
"REF7707, a threat campaign involving the FINALDRAFT, PATHLOADER, and GUIDLOADER malware families, provides details about how an espionage-motivated threat evaded defenses using Microsoft’s GraphAPI for C2."
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family used in the espionage-motivated REF7707 campaign, which evaded defenses using Microsoft GraphAPI for command-and-control.
An in-memory loader used to download encrypted payloads and execute them after decryption, observed only with FINALDRAFT payloads. Multiple 2023 samples showed minor download/decryption variations and signs of active development/testing.
A loader used with FINALDRAFT that retrieves, decrypts, and executes encrypted shellcode in memory. Samples used attacker domains, Firebase, Pastebin, and a Southeast Asian university storage system to stage payloads. Some observed samples contained debug strings or broken decryption routines, suggesting active development and testing.
In-memory shellcode loader/downloader observed in association with Finaldraft, used to execute encrypted shellcode without writing payloads to disk.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.