SADBRIDGE is a custom Windows loader used by the REF3864 intrusion set to deploy GOSAR, a Golang-based reimplementation of the Quasar remote-access trojan. It has targeted Chinese-speaking users through trojanized installers masquerading as legitimate software, commonly distributed in archive files from fraudulent software-download pages. Related activity appears to have operated since at least December 2023; the available evidence does not establish the operator’s identity or motivation.
SADBRIDGE abuses DLL side-loading to execute staged payloads, decrypts and decompresses those stages, and injects them into legitimate Windows processes. Its injection tradecraft includes APC injection, token manipulation, and PoolParty Variant 7 thread-pool injection. The loader can bypass UAC through COM-based elevation mechanisms and can create a SYSTEM-level scheduled task. It establishes persistence through an auto-start Windows service running under LocalSystem.
The loader impairs defensive monitoring by patching AMSI- and ETW-related functions and uses long sleep intervals to hinder sandbox analysis. It also checks for artifacts associated with Chinese security products. SADBRIDGE ultimately injects the GOSAR payload into trusted Windows processes, providing the final remote-access capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The custom SADBRIDGE loader is packaged in trojanized MSI installers, uses DLL side-loading and process injection, and deploys GOSAR as the final payload.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
SADBRIDGE integrates a public UAC bypass technique using the IElevatedFactorySever COM object to indirectly create the scheduled task. This task is configured to run DevQueryBroker.exe on a daily basis with SYSTEM level privileges.
SADBRIDGE uses the IElevatedFactoryServer COM object to create a scheduled task named DevQueryBrokerService that runs DevQueryBroker.exe daily with SYSTEM privileges.
SADBRIDGE integrates a public UAC bypass technique using the IElevatedFactorySever COM object to indirectly create the scheduled task. This task is configured to run DevQueryBroker.exe on a daily basis with SYSTEM level privileges.
SADBRIDGE uses the IElevatedFactoryServer COM object to create a scheduled task named DevQueryBrokerService that runs DevQueryBroker.exe daily with SYSTEM privileges.
SADBRIDGE uses PoolParty Variant 7 to inject shellcode into explorer.exe and subsequently into spoolsv.exe or lsass.exe via thread-pool I/O completion queues.
SADBRIDGE uses APC injection to queue decrypted GOSAR shellcode into a newly created process thread; the GOSAR plugin component also queues APCs in suspended msiexec.exe.
The loader attempts to duplicate the user token for a session, raises its integrity level to System integrity, and creates svchost.exe or dllhost.exe with CreateProcessAsUserA.
SADBRIDGE stores encrypted stages with a .log extension; GOSAR encrypts plugins, collected logs, and keylogger/clipboard data.
Campaign samples were hosted on landing pages masquerading as Telegram or the Opera GX browser, and installers bundled legitimate applications with malicious DLLs.
SADBRIDGE uses PoolParty Variant 7 to inject shellcode into explorer.exe and subsequently into spoolsv.exe or lsass.exe via thread-pool I/O completion queues.
SADBRIDGE uses APC injection to queue decrypted GOSAR shellcode into a newly created process thread; the GOSAR plugin component also queues APCs in suspended msiexec.exe.
The loader attempts to duplicate the user token for a session, raises its integrity level to System integrity, and creates svchost.exe or dllhost.exe with CreateProcessAsUserA.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom malware loader mentioned as prior context; it uses PoolParty Variant 7 and is designed to deploy GOSAR.
Malware family noted for also using the rare PoolParty Variant 7 process injection technique; mentioned as similar to ValleyRat, suggesting shared tooling or evolution within the same ecosystem.
Custom Windows malware loader delivered via trojanized MSI installers. It uses DLL side-loading, shellcode decryption, process injection, AMSI/ETW patching, UAC bypass via ICMLuaUtil, Task Scheduler abuse, and service/registry persistence to ultimately inject and launch GOSAR.
Windows loader delivered through malicious installers masquerading as legitimate software. It side-loads patched DLLs, decrypts staged payloads, bypasses UAC, establishes SYSTEM-level service persistence, disables AMSI and ETW, and injects GOSAR into svchost.exe or dllhost.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.