LgoogLoader is a Windows malware loader observed as a downstream payload in pay-per-install distribution chains associated with TaskLoader and also delivered in broader malware-delivery ecosystems such as NullMixer. It has been described as an installer that drops three components: a batch script, an AutoIt interpreter, and an AutoIt script, indicating a staged execution model built around AutoIt-based loading. Reported samples perform anti-debugging and anti-virtual-machine checks before injecting themselves into another process using RunPE-style process replacement or hollowing, reflecting a focus on defense evasion and in-memory execution. LgoogLoader has been seen alongside other commodity malware families in campaigns using pirated-software and crack-themed lures, where victims are redirected to malicious download sites and receive multi-stage payloads. Its role is primarily to execute or facilitate delivery of additional malware rather than to act as the final monetization payload. High-confidence reporting ties it to Windows-focused criminal malware operations rather than a specific named state actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
“it’s an obfuscated .NET binary… de4dot to deobfuscate… .NET binary that has been obfuscated with Reactor… decrypting them with simple xor operations… encrypted config”
“sitool.exe which has the Original Filename of sihost.exe to blend in with default Windows tools… tries to pass as a legitimate version of Windows Sysinternals ShellRunas tool… samples were trying to disguise as dxdiag.exe”
“DotRunpeX file to inject the malware into processes… it will then inject itself into another process using the injection technique RunPE… VirtualAllocEx and WriteProcessMemory… SetThreadContext… ResumeThread”
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Installer/loader that drops and executes a batch file alongside AutoIt components.
Loader that masquerades as a legitimate Sysinternals tool, uses XOR string decryption and dynamic API resolution, performs anti-VM/anti-debug checks (e.g., EDID/monitor checks, raw disk/MBR checks, exclusive file open), then uses RunPE-style process injection and attempts to download an encrypted configuration/payload over HTTP.
Loader family observed as an embedded payload delivered/injected by dotRunpeX.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.