FakeBat is a malware loader and Loader-as-a-Service (LaaS) platform used to distribute additional payloads. The content associates it with malvertising, SEO poisoning, fake software download sites, fake browser update lures, and abuse of Windows MSIX packages. Observed lures impersonated legitimate software and services including Slack, Notion, Grammarly, Microsoft Teams, Zoom, and other popular software downloads. FakeBat has been tracked by Microsoft as Storm-1113.
The malware is used to deliver follow-on payloads including RedLine, Gozi/Ursnif, Rhadamanthys, ArechClient2, IcedID, and other stealers. Reporting in the content also notes FakeBat-linked activity delivering payloads consistent with GHOSTPULSE via DLL sideloading, and that several loaders including FakeBat have delivered ArechClient2. In one January 2024 Slack-themed malvertising campaign, a Windows MSI/MSIX installer delivered FakeBat while a parallel macOS DMG delivered Atomic Stealer; the FakeBat sample hash was 49f12d913ad19d4608c1596cf24e7b6fff14975418f09e2c1ad37f231943fda3 and its command-and-control server was ads-strong[.]online. Related infrastructure in the same campaign included slack[.]trialap[.]com and redirectors ivchlo[.]gotrackier[.]com and red[.]seecho[.]net.
The content describes FakeBat activity in MSIX-based intrusion clusters from July to December 2023 in which adversaries used malvertising and/or SEO poisoning to trick victims into opening trojanized MSIX installers. In those cases, legitimate Advanced Installer components such as AiStub.exe and StartingScriptWrapper.ps1 were abused, with PowerShell execution, GPG decryption tools, and tar decompression noted as consistent with FakeBat tradecraft. FakeBat has also previously been used in MSIX packages to distribute additional payloads including IcedID. Multiple sources in the content state that MSIX package abuse has been observed in campaigns involving FakeBat/Storm-1113, and that malicious MSIX packages in recent campaigns were developer-signed rather than Microsoft Store signed.
The content also links FakeBat to broader malvertising ecosystems targeting business users via sponsored search results and fake download pages. These campaigns have used payloads such as FakeBat, Nitrogen, and HijackLoader, and often lead to commodity infostealer infections. FakeBat is additionally mentioned as using fake browser update techniques, though less commonly than threats such as SocGholish or Scarlet Goldfinch.
A related custom loader named MaskBat, used by the GrayAlpha cluster overlapping with FIN7, is described as a customized variant with similarities to FakeBat. GrayAlpha used fake browser update pages, fake 7-Zip download sites, and TAG-124 traffic distribution to deliver NetSupport RAT, but the content only states similarity between MaskBat and FakeBat rather than identifying FakeBat itself as the GrayAlpha loader.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In these campaigns, GrayAlpha employed two primary types of PowerShell loaders: a self-contained custom script known as PowerNet, and a dynamic loader — a customized variant of FakeBat — referred to as MaskBat.
MSIX packages have been leveraged by threat actors such as FIN7, Zloader (Storm-0569), and FakeBat (Storm-1113) for malware delivery.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The downloaded file was a VHD container which, when mounted, revealed Installer.bat, a batch file containing simple commands intended to raise execution privileges; add scanning exclusions for Windows Defender; and download and execute a remote batch script and an executable.
Insikt Group identified another custom loader, referred to as MaskBat, which has similarities to FakeBat but is obfuscated and contains strings linked to GrayAlpha.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as malware associated with MSIX package abuse.
FakeBat is referenced as malware observed in recent malicious MSIX package campaigns using developer-signed MSIX packages.
Loader closely resembling BatLoader with slightly different TTPs; used in malvertising campaigns that lead to infostealer infections such as RedLine, Gozi/Ursnif, and Rhadamanthys.
Malware referenced as being delivered via MSIX packages for malware delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.