BatCloak is a Windows batch-file obfuscation engine used to protect and deploy malware through heavily obfuscated .bat/CMD scripts designed to be fully undetectable (FUD) and to evade security controls. Trend Micro reported BatCloak-obfuscated batch files being used from at least September 2022 through June 2023 to load various malware families and exploits, with persistent evasion against security solutions; in a set of 784 samples, the average detection rate was reported as less than one, and 80% of retrieved samples had zero detections. The engine functions as a modular loading mechanism and is associated in the provided content with SeroXen, whose newer iterations reportedly incorporated an updated BatCloak engine as the loader. More broadly, BatCloak is cited by Securonix as part of the DOSfuscation ecosystem, where attackers use obfuscated batch/CMD commands—often launched via malicious .lnk shortcut files—to reduce antivirus/EDR detection and hinder analysis. The content attributes to this ecosystem techniques such as string splitting with caret escapes or quotes, variable substitution and delayed expansion, substring/index extraction, and encoding manipulation. High-confidence indicators in the provided content are limited; the source notes that Trend Micro later updated its BatCloak research with indicators of compromise, but those specific IOCs are not included in the supplied material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An obfuscation engine used to heavily obfuscate Windows batch/DOS scripts to evade detection.
A highly evasive batch-file obfuscation engine used to produce heavily obfuscated, low-detection (FUD) Windows batch scripts that can act as a loader mechanism to deploy other malware families and potentially exploits, enabling persistent evasion of security solutions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.