DBatLoader is a malware loader observed in phishing-driven intrusion chains and referenced alongside other loaders such as Amadey, DarkGate, and GuLoader. The provided content places it in campaigns abusing Windows LNK shortcut files and PowerShell-based execution, and notes that PowerShell is used by DBatLoader to evade detection and download additional payloads. DBatLoader has also been mentioned as being deployed alongside other malware, including DarkCloud and ClipBanker, and in a phishing campaign distributing WarZone RAT via DBatLoader. High-confidence details in the content indicate its role is as a loader used to stage or launch follow-on malware rather than as the final payload. The content does not provide specific DBatLoader-exclusive IOCs, persistence mechanisms, or technical internals beyond its association with phishing, LNK abuse, and PowerShell-enabled payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader mentioned as being deployed alongside DarkCloud in some campaigns.
Related [QuickNote] Phishing email distributes WarZone RAT via DBatLoader
Referenced as a malware family that commonly abuses PowerShell for execution and delivery/easion activities.
Loader malware family mentioned as being delivered via LNK phishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.