Quant Loader is a low-cost malware downloader used as an intermediate stage in criminal intrusion chains, notably by TA505 during early 2018. It has been observed as a simple first-stage payload whose primary role is to retrieve and execute additional malware on compromised Windows systems rather than provide extensive post-compromise functionality itself. In documented campaigns, Quant Loader was used to fetch follow-on payloads including the FlawedAmmyy remote access trojan.
TA505 employed Quant Loader in email-driven infection chains that relied on social engineering and malicious attachments. Observed delivery patterns included spam or phishing messages carrying archive attachments that contained Internet Shortcut files, which triggered retrieval of malicious JavaScript over SMB; that JavaScript then downloaded Quant Loader, which in turn installed the final payload. TA505 also broadly used attachment-based phishing formats during this period, but the directly supported Quant Loader chain is the JavaScript-to-downloader-to-RAT sequence associated with mass email campaigns in March through April 2018.
Quant Loader is associated with commodity malware distribution on the cybercriminal underground and appears to have been used as a straightforward staging component in larger operations. Its role in TA505 activity reflects the group’s transition from pure malware spam toward multi-stage delivery chains that separated initial user interaction, downloader execution, and final payload deployment. High-confidence reporting supports its use on Windows hosts as a downloader rather than a full-featured backdoor or RAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Quant Loader est un simple code de téléchargement disponible à bas prix sur le marché noir. Le mode opératoire y a eu recours de janvier à avril 2018.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
TA505 seems to have distributed its malware only through phishing email campaigns... The only infection vector currently known to be used by the TA505 intrusion set is phishing emails including a malicious attachment or link.
"FlawedAmmyy Admin appeared most recently as the payload in massive email campaigns... The messages in these campaigns contained zipped .url attachments..." and "Emails contained an attachment ...doc ... which used macros to download the FlawedAmmyy malware directly."
This JavaScript in turn downloads Quant Loader, which, in this case, fetched the FlawedAmmyy RAT as the final payload.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Intermediate loader used in TA505 campaigns; delivered after initial attachment execution and used to fetch the final payload (notably FlawedAmmyy).
Loader/downloader used in the infection chain to retrieve and execute the final payload (FlawedAmmyy), with observed C2 and payload distribution infrastructure in the campaign IOCs.
A malware loader downloaded by JavaScript that retrieves and delivers FlawedAmmyy as the final payload.
Stage-1 downloader used by TA505 early in 2018 to deploy follow-on payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.