BatLoader is a Windows initial-access malware family and loader first observed in 2022 that is widely used to establish a foothold and deliver follow-on payloads. It is commonly associated with the intrusion set tracked as Water Minyades and has been used by multiple financially motivated actors, including in intrusion chains that later led to Royal, BlackSuit, Black Basta, Hive, and ALPHV/BlackCat-related activity. BatLoader has repeatedly been observed delivering additional malware such as Ursnif/ISFB, Vidar, RedLine, SystemBC, ZLoader, QakBot, Bumblebee, Cobalt Strike, and remote monitoring and management tools including Atera and Syncro.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In June 2023, Trend Micro observed an upgrade to the evasion techniques used by the Batloader initial access malware... The group behind Batloader ... have begun employing Pyarmor Pro ... to obfuscate its main malicious python scripts.
One such threat that has been particularly prevalent over the last couple of months is BatLoader. Named by Mandiant, BatLoader is an initial access malware that heavily uses batch and PowerShell scripts to gain a foothold on a victim machine and deliver other malware.
Malsmokeと呼ばれる攻撃キャンペーンを実行している攻撃グループであり、Batloaderと呼ばれるマルウェアを使用しており、DEV-0569やWater Minyadesと重複があります。
Malsmokeと呼ばれる攻撃キャンペーンを実行している攻撃グループであり、Batloaderと呼ばれるマルウェアを使用しており、DEV-0569やWater Minyadesと重複があります。
32 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Tactic Initial Access ID T1189 MITRE ATT&CK Technique Drive-by Compromise Description BatLoader is delivered via fake software installers
The malicious actor(s) create a custom action to run the malicious PowerShell inline script. The malicious script resides under AI_DATA_SETTER action name and contains the instructions to download the malicious update.bat file from the C2 domain
The MSI File executes the following command line: "C:\Windows\System32\cmd.exe" /c ... Python2.bat
it will execute a User Account Control (UAC) prompt via a file named getadmin.vbs
the script recursively removes the implementation of Windows Defender IOfficeAntiVirus under HKLM:\SOFTWARE\Microsoft\AMSI\Providers\{2781761E-28E0-4109-99FE-B9D127C57AFE}. It then adds the extensions such as exe and DLL as exclusions to Windows Defender.
Batloader executes open-sourced scripts that attempt to stop services related to security software, such as Windows Defender.
BatLoader’s stealth and persistence are what made this malware stand out from the rest during its latest campaign.
The group behind Batloader ... have begun employing Pyarmor Pro ... to obfuscate its main malicious python scripts.
It creates a temporary bat file to copy itself to %temp% location and later deletes the bat file and starts execution of dropped file.
OpenSSL is used to decrypt the downloaded file ( a.exe.enc ) using AES-256 encryption ... The decrypted result is then saved in the file named control.exe
Recent samples analyzed by TRU utilize Windows Installer files masquerading as the above applications
the script retrieves the Cobalt Strike payload named installv2.dll ... and runs it via rundll32.exe with an ordinal “SRANdomsrt”
the script will attempt to fingerprint the network infrastructure of the victim environment by executing arp.exe , mapping IP addresses to MAC addresses and retrieving the domain name via the WMI command-line (WMIC) utility.
The victim’s network infrastructure is fingerprinted using the following commands: whoami /groups
This information is then sent to the command-and-control (C&C) server, which is countingstatistic[.]com in this case.
Modify Defender settings to exclude paths, processes, and file extensions.
The last BatLoader campaign performs the antivirus checks and is capable of modifying Windows UAC prompt, disabling Windows Defender notifications, disabling Task Manager, disabling command prompt, preventing users from accessing Windows registry tools, disabling the Run command
234 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another loader family used in drive-by download campaigns; later referenced as being distributed via fake software sites impersonating IT software such as Slack and AnyDesk.
Initial access malware loader used in SEO poisoning and malvertising chains to download additional payloads such as Raccoon Stealer, Gozi/Ursnif, Stealc, and Cobalt Strike.
Loader malware referenced as delivering/decrypting a payload tied to recent Ursnif campaigns.
A loader referenced as leveraging obfuscated DOS/batch scripts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.