LDR4 is a Windows malware loader associated with the RM3 branch of the ISFB/Gozi ecosystem and used as part of cybercriminal initial-access operations. It emerged in 2022 as a later-stage evolution of the long-running ISFB family, reflecting that ecosystem’s shift away from traditional banking fraud toward loader activity and enablement of follow-on intrusions. Reporting links LDR4 to the RM3 group and to broader criminal distribution activity involving actors such as TA584, which used it as an initial-access payload during 2022–2023.
LDR4 is designed to load and execute additional malicious payloads and has been described as incorporating modular functionality beyond simple staging, including VNC, SOCKS proxying, and keylogging for second-stage operations. Within the wider ISFB lineage, these capabilities align with credential theft, remote access, and post-compromise enablement. Its role in campaigns indicates use as an access-enabling component that can support subsequent malware deployment, including ransomware-related operations.
Observed distribution contexts place LDR4 in email-driven intrusion activity and botnet-backed malware delivery chains. It has been seen in campaigns attributed to TA584 and in distributions associated with Cutwail-linked operations. The malware targets Windows environments and is best understood as a loader used by financially motivated threat actors to establish footholds and deliver additional tooling during the early phases of intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“...payloads for initial access: Ursnif (2020 – 2022), LDR4 (2022 – 2023)…”
12 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously used loader associated with TA584 campaigns (mentioned historically).
Referenced as a historical payload used by TA584 (no additional details provided in the content).
Payload historically used by TA584 (no additional behavior details provided in the content).
Previously used payload by TA584 for initial access (2022–2023).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.