NETXLOADER is a highly obfuscated loader written in .NET. It has been used by Qilin ransomware-as-a-service affiliates, including activity observed in November 2024. The loader functions as an initial-stage malware component that stealthily deploys additional payloads, including ransomware and other loaders such as SmokeLoader. Qilin-associated activity has used NETXLOADER to support ransomware intrusions, including deployment of Agenda/Qilin ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware loader reportedly adopted by Qilin affiliates in 2024 and 2025.
Previously undocumented .NET-based loader used in campaigns associated with Qilin-linked activity.
.NET-compiled loader used by Qilin operators/affiliates in intrusions (likely for staging or delivering additional payloads).
NETXLOADER is a .NET-based loader mentioned as being used by Qilin affiliates in a November 2024 campaign, likely to stage or deliver ransomware-related payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.