EugenLoader is a Windows Trojan/loader delivered via malicious signed MSIX packages, frequently through abuse of the Windows App Installer ms-appinstaller URI scheme. Microsoft reported Storm-1113 as the developer of EugenLoader, first observed around November 2022, and observed it being distributed since at least mid-November 2023 through search advertisements and spoofed software download pages, including Zoom-themed lures. Microsoft also observed Sangria Tempest (FIN7/Carbon Spider/ELBRUS) using Storm-1113’s EugenLoader via malicious MSIX installations in November-December 2023.
Its primary role is to deliver additional payloads. Microsoft associated EugenLoader follow-on payloads with Gozi, RedLine Stealer, IcedID, Smoke Loader, NetSupport Manager (NetSupport RAT), Sectop RAT, and Lumma Stealer. In FIN7-linked activity, Microsoft stated EugenLoader was used to inject Carbanak, which then delivered the Gracewire implant. Related FIN7 MSIX campaigns also used highly obfuscated PowerShell such as POWERTRASH to load NetSupport and Gracewire.
The infection vector described in the reporting is malvertising/SEO-poisoning and spoofed software download sites that present App Installer/MSIX-based installs. Microsoft assessed this vector was attractive because it could bypass protections such as SmartScreen and browser executable-download warnings. Silent Push separately described FIN7-associated MSIX distribution templates that displayed a "Requires Browser Extension!" pop-up and were observed in malvertising contexts such as Google ads.
Infrastructure and indicator context directly mentioned in the content includes ThreatFox-marked EugenLoader domains such as protonpin[.]com, and Passive DNS pivoting on IP 206.206.123[.]151 revealing multiple domains associated with EugenLoader. The malware is associated in the reporting with Storm-1113 as an access broker and malicious-installer provider, and with FIN7/Sangria Tempest in campaigns that can lead to data theft, extortion, or ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In December of 2023, Microsoft also observed FIN7 using MSIX malware and a Windows Trojan, EugenLoader, to inject Carbanak...
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
EugenLoader is a loader malware used to deliver additional malicious payloads. It is identified through domain and IP infrastructure analysis.
A Windows trojan/loader used by FIN7 in MSIX-based campaigns to facilitate follow-on payload injection (notably Carbanak, per the content).
Commodity loader delivered via malicious MSIX/App Installer and malvertising; used to stage additional payloads (stealers, RATs, other loaders).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.