WMLOADER is a Windows loader used to decrypt and execute the NANOREMOTE backdoor in memory. It has masqueraded as legitimate security software, including Bitdefender and Trend Micro products, while using invalid signatures. WMLOADER allocates and changes memory protections for embedded shellcode, decrypts that shellcode with a rolling-XOR routine, and uses it to AES-CBC decrypt an adjacent payload before launching the resulting implant without writing the decrypted payload to disk. It has been observed in an espionage-related intrusion chain associated with NANOREMOTE; cryptographic and deployment overlaps also support a relationship with the FINALDRAFT/REF7707 activity ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The shellcode is located at RVA (0x193041) and decrypted using a rolling XOR algorithm... wmsetup.log... [is decrypted] using AES-CBC.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader component that masquerades as a legitimate security executable, decrypts an encrypted payload (AES-CBC) from a file (wmsetup.log), and launches NANOREMOTE in-memory to reduce on-disk artifacts and evade file-based detection.
WMLOADER is a loader malware that masquerades as a legitimate Bitdefender (or Trend Micro) executable. It prepares the environment for shellcode execution, decrypts and loads the NANOREMOTE backdoor into memory, and uses a hard-coded AES key for decryption. It is part of the same development process as NANOREMOTE and FINALDRAFT.
Windows loader that masquerades as a Bitdefender security program, decrypts embedded shellcode (rolling XOR), then decrypts a local file (wmsetup.log) using AES-CBC and executes the resulting payload in memory (observed delivering NANOREMOTE; also shown capable of decrypting and loading FINALDRAFT).
A Windows loader masquerading as a Bitdefender Security program, such as BDReinit.exe, using an invalid digital signature. It decrypts embedded shellcode with rolling XOR; that shellcode AES-CBC decrypts a wmsetup.log file and executes the resulting NANOREMOTE or FINALDRAFT payload in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.