PicassoLoader is a downloader toolkit and payload delivery malware family associated with the Ghostwriter activity cluster, also tracked as UNC1151, UAC-0057, FrostyNeighbor, TA445, Blue Dev 4, and Moonscape. Reporting links it with medium confidence to Belarus-aligned cyberespionage activity targeting primarily Ukrainian government, military, and defense entities, as well as Belarusian opposition activists; additional targeting has included industrial, healthcare, logistics, and government organizations in Poland and Lithuania.
Observed infection vectors include weaponized Microsoft Excel documents with malicious VBA macros, malicious RAR archives exploiting CVE-2023-38831 in WinRAR, spearphishing PDFs that lead to geofenced payload delivery, and JavaScript-based staging chains. Variants of PicassoLoader have been documented in .NET, PowerShell, JavaScript, and C++. In multiple campaigns, macro-enabled XLS files dropped and executed DLL payloads via regsvr32.exe or rundll32.exe; other chains used BAT/LNK/mshta execution or delivered JavaScript loaders inside RAR archives.
Its core role is host profiling and staged payload retrieval. Reported behaviors include collecting system information such as username, computer name, OS version, boot time, current time, and running processes; sending that data to attacker-controlled servers via HTTP POST; and downloading or executing follow-on payloads, often selectively after operator review of victim profiling data. Multiple reports state that PicassoLoader has been used to deliver Cobalt Strike Beacon. In some cases, payloads were disguised as images or embedded in SVG, CSS, JS, or other web-associated content; one CERT-UA report described a JavaScript variant downloading an SVG file, extracting embedded data, decrypting a .NET payload with the Rabbit algorithm, and leading to Cobalt Strike Beacon deployment.
Additional observed tradecraft includes use of ConfuserEx-protected .NET assemblies, self-modifying in-memory behavior, PE-header tampering to hinder .NET parsing, decoy document display, persistence via HKCU Run keys and scheduled tasks, use of LOLBins such as regsvr32.exe, rundll32.exe, MSBuild.exe, and mshta.exe, and in some variants an in-memory helper DLL named LibCMD.dll to launch cmd.exe with redirected stdin/stdout. Reported file and artifact examples tied to PicassoLoader activity include Dwnldr.dll, Loader.dll, ResetEngine.dll, Update.js, certificate.js, EdgeTaskMachine.js, sdfhui2kjd.js, %APPDATA%\Microsoft\runbll32.dll, %AppData%\Microsoft\ruhbll32.dll, and persistence via a scheduled task named "System service."
Reported infrastructure associated with PicassoLoader campaigns includes domains such as backstagemerch.shop, empoweringparents.shop, lauramcinerney.shop, americandeliriumsociety.shop, cookingwithbooks.shop, everythingandthedog.shop, pigglywigglystores.shop, sciencealert.shop, attachment-storage-asset-static.needbinding.icu, book-happy.needbinding.icu, easiestnewsfromourpointofview.algsat.icu, mickeymousegamesdealer.alexavegas.icu, hinesafar.sardk.icu, and shinesafar.sardk.icu. High-confidence examples of lure themes include Ukrainian local self-government reform, USAID/DAI HOVERLA, taxation and financial topics, anti-corruption initiatives, Ukrainian military logistics reporting, Belarusian political prisoners, and Ukrtelecom-themed communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Key developments include the deployment of multiple variants of the group’s main payload downloader, named PicassoLoader by CERT-UA. Variants of this downloader are written in .NET, PowerShell, JavaScript, and C++.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysis of Dwnldr.dll shows that it is a DLL file with a .NET assembly embedded inside. The file is protected with ConfuserEx... The DLL file hosts a payload that appears to be a simplified variant of PicassoDownloader, a malware family also linked to Ghostwriter activity... Analysis of techniques used by threat actors can often be helpful in establishing the origin of the attack and the malware it uses. In this case... allowing us to establish a medium confidence link between them and a malware cluster known as PicassoLoader, a downloader toolkit.
Analysis of Dwnldr.dll shows that it is a DLL file with a .NET assembly embedded inside. The file is protected with ConfuserEx... The DLL file hosts a payload that appears to be a simplified variant of PicassoDownloader, a malware family also linked to Ghostwriter activity... Analysis of techniques used by threat actors can often be helpful in establishing the origin of the attack and the malware it uses. In this case... allowing us to establish a medium confidence link between them and a malware cluster known as PicassoLoader, a downloader toolkit.
Analysis of Dwnldr.dll shows that it is a DLL file with a .NET assembly embedded inside. The file is protected with ConfuserEx... The DLL file hosts a payload that appears to be a simplified variant of PicassoDownloader, a malware family also linked to Ghostwriter activity... Analysis of techniques used by threat actors can often be helpful in establishing the origin of the attack and the malware it uses. In this case... allowing us to establish a medium confidence link between them and a malware cluster known as PicassoLoader, a downloader toolkit.
Analysis of Dwnldr.dll shows that it is a DLL file with a .NET assembly embedded inside. The file is protected with ConfuserEx... The DLL file hosts a payload that appears to be a simplified variant of PicassoDownloader, a malware family also linked to Ghostwriter activity... Analysis of techniques used by threat actors can often be helpful in establishing the origin of the attack and the malware it uses. In this case... allowing us to establish a medium confidence link between them and a malware cluster known as PicassoLoader, a downloader toolkit.
For Ukrainian IP addresses, it delivers a RAR archive containing a JavaScript file. This file executes a JavaScript version of PicassoLoader, the group's payload downloader, which collects system information and sends it to attacker-controlled servers.
Key developments include the deployment of multiple variants of the group’s main payload downloader, named PicassoLoader by CERT-UA. Variants of this downloader are written in .NET, PowerShell, JavaScript, and C++.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
CERT-UA ... зафіксовано сплеск активності угрупування UAC-0057, що полягала в розповсюдженні документів з макросами ... Вміст виявлених файлів ... стосувався реформи органів місцевого самоврядування ... оподаткування, а також тематики фінансово-економічних показників.
... документи з макросами, призначеними для запуску ... PICASSOLOADER ...
The XLS document contains an obfuscated VBA macro... For this script, the attackers used a popular obfuscator tool called Macropack.
та виконання JavaScript-коду, призначеного для завантаження зображення "113-1131910-clipart.svg", отримання за зміщенням та дешифрування за допомогою алгоритму Rabbit .NET-файлу
The file is protected with ConfuserEx... For this script, the attackers used a popular obfuscator tool called Macropack.
Once the file is downloaded, it is renamed and then saved to %APPDATA%\Roaming\Microsoft\SystemCertificates\CertificateCenter.dll ... This suggests that the CertificateCenter.dll file is not a binary as the file extension would suggest but rather contains program source code.
T1036.005 Masquerading: Match Legitimate Resource Name or Location
It does so by decrypting additional code of the assembly.
The DLL file is loaded with the following command line invocation: C:\Windows\System32\regsvr32.exe /u /s "C:\Temp\Realtek(r)Audio.dll"
the .NET ConfuserEx-obfuscated Downloader DLL ... is loaded with rundll32.exe and respective commandline arguments to run an exported function.
As a part of application protection provided by the obfuscator, the Downloader creates a copy of itself in memory, and then modifies it... It also uses a clever evasion technique, altering its own PE header in memory and breaking internal links to the .NET assembly.
Мережеві: backstagemerch[.]shop, empoweringparents[.]shop, lauramcinerney[.]shop ... https://backstagemerch.shop/the-simpsons/mens-freeze.html ...
Command and Control T1071.001 Application Layer Protocol: Web Protocols
the Downloader writes a decoy Excel workbook file ... and downloads additional file(s) from the Web... Once the decoy Excel file is opened, the Downloader attempts to fetch the next stage from the following URL
136 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader malware used in a separate Ghostwriter campaign targeting Belarusian opposition activists and Ukrainian military and government entities via weaponized Excel documents.
Loader used by UAC-0057 (Ghostwriter).
A payload downloader used by FrostyNeighbor/Ghostwriter that collects system information and sends it to attacker-controlled servers, after which operators may choose to deliver a third-stage payload.
A long-standing payload downloader used by Ghostwriter/FrostyNeighbor. In this campaign, a JavaScript variant profiles the compromised host, collects system information such as username, machine name, OS version, boot time, and running processes, then reports to attacker-controlled servers every ten minutes. Based on operator review, it may receive and launch a further payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.