DPLoader is a Windows downloader used by the Larva-25012 cybercriminal group in proxyjacking operations, primarily affecting systems in South Korea. JavaScript- and Python-based variants establish persistence through Windows Task Scheduler, collect basic host information, periodically communicate with command-and-control infrastructure, and execute received PowerShell commands. Those commands install proxyware that monetizes a victim’s Internet bandwidth, including DigitalPulse, Infatica, Honeygain, SOAX, Appsalt, and IPRoyal. DPLoader has been deployed through trojanized installers masquerading as legitimate software, including applications sought from cracked-software portals. Observed installation chains use DLL side-loading, in-memory payload execution, PowerShell staging, and installation of Node.js or Python to run DPLoader. Associated activity has also impaired Microsoft Defender protections and used process injection for deployed proxyware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DPLoader (versions JavaScript et Python) est relancé sur des systèmes déjà infectés, collecte les informations système, les transmet périodiquement au C2 et exécute des commandes PowerShell reçues afin d’installer des Proxyware.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
« Enregistré dans le Planificateur de tâches Windows pour persistance » ; les proxywares créent notamment les tâches PlutonAgentScheduler, EnterpriseMgmtServicesScheduler, SecurityHealthServiceSyncUpdate et BackgroundTaskRegistrationMaintenanceTaskScheduler.
“DPLoader collects basic system information and periodically transmits it to the C&C server” and the SOAX PowerShell script “reports execution results or error logs” to an HTTP URL.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader JavaScript/Python utilisé pour la persistance via des tâches planifiées Windows, la collecte d’informations système, le reporting C2 et l’exécution de PowerShell qui installe des charges utiles de proxyware.
A JavaScript- or Python-based loader that establishes scheduled execution, gathers basic host information, communicates with a C2 server, and executes PowerShell commands to install proxyware payloads.
Multi-language loader (JavaScript and Python variants) created post-infection to communicate with C2, retrieve instructions, and install proxyware modules; established via Task Scheduler for persistence.
A downloader/loader installed via DLL side-loading that persists via Windows Task Scheduler and contacts a C2 server to retrieve commands and likely additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.