HeaconLoad is a Golang-based downloader deployed in a Windows malware distribution operation associated with BoryptGrab. It gathers system information, communicates with command-and-control infrastructure, and retrieves and executes additional payload bundles. It establishes persistence through Windows Registry-based mechanisms and scheduled tasks. HeaconLoad has been delivered within malicious ZIP bundles distributed through SEO-poisoned GitHub repositories and deceptive software-download pages, alongside BoryptGrab and other payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader nommé dans la liste de logiciels malveillants/outils, sans description de son rôle opérationnel dans cette campagne.
A Golang downloader reported as a secondary payload in BoryptGrab campaigns.
A Golang loader referenced as a secondary payload in prior BoryptGrab reporting, not the main malware analyzed here.
Golang-based downloader/loader used to fetch and execute additional payloads in the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.