BatLoader is a Windows initial-access malware family and loader first observed in 2022 that is widely used to establish a foothold and deliver follow-on payloads. It is commonly distributed through malvertising, SEO poisoning, and fake software download pages that impersonate popular business and consumer applications. Delivery has frequently relied on oversized MSI installers and, in some campaigns, JavaScript, archive, or other script-based stages designed to evade sandboxing and antivirus inspection.
BatLoader heavily abuses batch scripts, PowerShell, Python, and legitimate administration utilities during execution. Observed behavior includes privilege escalation via UAC prompts, host profiling, domain and network discovery, antivirus checks, and selective payload delivery based on victim characteristics such as domain membership or local network context. It has also been observed impairing defenses by adding Microsoft Defender exclusions, suppressing security notifications, modifying UAC-related settings, and using legitimate tools such as NSudo, NirCmd, Gpg4win, WinRAR, and OpenSSL to elevate privileges, decrypt payloads, or blend into normal system activity. Some variants use PyArmor-obfuscated Python components and other obfuscation or polyglot techniques to hinder analysis and detection.
BatLoader is best understood as a distribution and loading platform rather than a single-purpose payload. It has delivered a broad range of secondary malware and tooling, including Ursnif/ISFB, Vidar, RedLine, SystemBC, QakBot, ZLoader, Bumblebee, SmokeLoader, Raccoon Stealer, Cobalt Strike, and remote monitoring and management tools such as Atera and Syncro. In enterprise intrusions, BatLoader infections have repeatedly preceded hands-on-keyboard activity and ransomware deployment, including cases associated with Royal, BlackSuit, Hive, and ALPHV/BlackCat intrusion chains.
Multiple vendors track the operator or intrusion set behind major BatLoader activity as Water Minyades, and some reporting also overlaps this activity with DEV-0569 and SteelClover. Campaigns have targeted organizations across sectors including manufacturing, healthcare, finance, insurance, consulting, telecommunications, retail, nonprofit, education, and government, with substantial activity observed in North America, Europe, and Japan. BatLoader remains a significant malware loader because it combines effective social-engineering distribution with flexible post-download execution and selective delivery of high-impact follow-on payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In June 2023, Trend Micro observed an upgrade to the evasion techniques used by the Batloader initial access malware... The group behind Batloader ... have begun employing Pyarmor Pro ... to obfuscate its main malicious python scripts.
One such threat that has been particularly prevalent over the last couple of months is BatLoader. Named by Mandiant, BatLoader is an initial access malware that heavily uses batch and PowerShell scripts to gain a foothold on a victim machine and deliver other malware.
Malsmokeと呼ばれる攻撃キャンペーンを実行している攻撃グループであり、Batloaderと呼ばれるマルウェアを使用しており、DEV-0569やWater Minyadesと重複があります。
Malsmokeと呼ばれる攻撃キャンペーンを実行している攻撃グループであり、Batloaderと呼ばれるマルウェアを使用しており、DEV-0569やWater Minyadesと重複があります。
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial access techniques include malvertising, callback phishing ... and forum or blog comments containing malicious links. These lead to downloads of malware, including BATLOADER and Qakbot, which in turn deliver secondary payloads that eventually lead to ransomware deployment.
Drive by social-engineering attacks remains a popular vector for various malware loaders.
Initial access techniques include malvertising, callback phishing (the use of a false payment or subscription confirmation message to lead a target to call a telephone number controlled by the attackers, who direct victims to download malicious files once they call), and forum or blog comments containing malicious links.
The malicious actor(s) create a custom action to run the malicious PowerShell inline script. The malicious script resides under AI_DATA_SETTER action name and contains the instructions to download the malicious update.bat file from the C2 domain
The MSI File executes the following command line: "C:\Windows\System32\cmd.exe" /c ... Python2.bat
it will execute a User Account Control (UAC) prompt via a file named getadmin.vbs
Batloader executes open-sourced scripts that attempt to stop services related to security software, such as Windows Defender.
The group behind Batloader ... have begun employing Pyarmor Pro ... to obfuscate its main malicious python scripts.
It creates a temporary bat file to copy itself to %temp% location and later deletes the bat file and starts execution of dropped file.
OpenSSL is used to decrypt the downloaded file ( a.exe.enc ) using AES-256 encryption ... The decrypted result is then saved in the file named control.exe
Recent samples analyzed by TRU utilize Windows Installer files masquerading as the above applications
the script retrieves the Cobalt Strike payload named installv2.dll ... and runs it via rundll32.exe with an ordinal “SRANdomsrt”
the script will attempt to fingerprint the network infrastructure of the victim environment by executing arp.exe , mapping IP addresses to MAC addresses and retrieving the domain name via the WMI command-line (WMIC) utility.
The victim’s network infrastructure is fingerprinted using the following commands: whoami /groups
This information is then sent to the command-and-control (C&C) server, which is countingstatistic[.]com in this case.
Modify Defender settings to exclude paths, processes, and file extensions.
The last BatLoader campaign performs the antivirus checks and is capable of modifying Windows UAC prompt, disabling Windows Defender notifications, disabling Task Manager, disabling command prompt, preventing users from accessing Windows registry tools, disabling the Run command
234 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another loader family used in drive-by download campaigns; later referenced as being distributed via fake software sites impersonating IT software such as Slack and AnyDesk.
BATLOADER is described as malware used in earlier stages of Royal attacks to deliver secondary payloads that can ultimately lead to ransomware deployment.
Initial access malware loader used in SEO poisoning and malvertising chains to download additional payloads such as Raccoon Stealer, Gozi/Ursnif, Stealc, and Cobalt Strike.
Loader malware referenced as delivering/decrypting a payload tied to recent Ursnif campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.