StarLoader is a Windows malware loader associated with staged execution of shellcode. It decrypts and executes shellcode from an external payload file and has been observed masquerading as legitimate software update packages, including software commonly associated with Adobe Acrobat Reader and Intel, to reduce suspicion and improve execution success. Its observed tradecraft centers on payload decryption and execution rather than standalone espionage or destructive functionality, making it most accurately characterized as a loader used to launch subsequent malicious code. High-confidence reporting supports defense-evasion through masquerading and post-compromise payload staging on Windows systems, but broader attribution, targeting, and downstream payload objectives are not established from the available information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader malware that decrypts and executes shellcode from a file.
Loader malware that disguises itself as legitimate software update packages.
Loader malware that decrypts and executes shellcode from a file.
Loader that masquerades as legitimate software update packages to trick users into execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.