MemLoader is a backdoor associated with the Mysterious Elephant advanced persistent threat group. It has been linked to a cyber-espionage campaign targeting diplomatic entities in South Asia, including activity reported to steal WhatsApp data. MemLoader has also been described as a custom module used alongside BabShell and other customized tools in Mysterious Elephant operations. A component identified as MemLoader has exhibited obfuscation and arbitrary shellcode-execution capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dropped malware MD5 ... bea602695d58cbf25fff058834e36c1d | MemLoader.dll ... Malware using hwp decoy file ... MemLoader.dll (png) ... MemLoader.dll (hwp).
Mysterious Elephant APT Campaign Targets South Asian Diplomacy, Steals WhatsApp Data with New MemLoader Backdoor
2 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader/downloader family referenced in related spoofing-page and decoy-document delivery chains. It appears as an intermediate payload used to load or deliver later-stage malware.
A loader delivered via fake security software installers (nos-setup.exe and astx-setup.exe). It is written to ProgramData as a .dat file and is used as an additional malicious payload in the broader campaign.
A newly referenced backdoor used in a cyber-espionage campaign targeting South Asian diplomacy and stealing WhatsApp data.
Customized loader module used by the Mysterious Elephant APT in recent campaigns (exact functionality not detailed in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.