BabbleLoader is a Windows malware loader designed to evade machine-learning-based endpoint defenses and EDR products through extensive junk code, meaningless control flow, unused strings, custom string and API obfuscation, and direct-syscall techniques. The analyzed sample (SHA256: a08db4c7b7bacc2bacd1e9a0ac7fbb91306bf83c279582f5ac3570a90e8b0f87) was reported as delivered through infrastructure associated with Amadey, specifically IP address 185.215.113.117 in AS51381 (1337team Limited / ELITETEAM). Based on overlap with Amadey infrastructure and related hosting observations, the content assesses BabbleLoader as likely originating from Russian threat actors.
Reverse engineering showed that BabbleLoader begins with long junk-code loops of memory writes and XOR operations intended to hinder analysis. It decrypts stack-string arrays with a custom XOR-and-bit-rotation algorithm using an initial key of 0x375b879a and multiplying the key by 0x4F on each iteration; this was used to recover strings such as ntdll.dll. The malware obtains ntdll.dll via GetModuleHandleA, manually validates DOS and NT headers, parses the NtDLL export directory, and resolves APIs through a custom hashing routine rather than normal imports. Recovered resolved APIs include NtCreateSection, NtMapViewOfSection, NtUnmapViewOfSection, NtClose, NtQuerySystemInformation, RtlAllocateHeap, and RtlFreeHeap.
The analysis concludes that BabbleLoader implements Halo’s Gate to evade hooked syscall stubs by locating neighboring unhooked stubs and deriving syscall IDs. It checks for expected syscall stub bytes (4c 8b d1 b8 followed by two zero bytes) and treats opcode 0xe9 as evidence of a hooked function. It also performs direct syscall execution by collecting syscall offsets and jumping directly to syscall stubs; dynamic analysis indicated one stored address corresponded to ZwResumeThread.
Observed capabilities include XOR operations, PE parsing, and stack strings. A YARA rule named babbleloader_112024 dated 2025-01-27 was published to detect BabbleLoader based on its custom algorithms and syscall-evasion patterns, and reportedly identified three additional samples via Unpac.me YARA Hunt.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
it was identified that the samples (SHA256 above) were delivered to victims through a C&C infrastructure, which is also used by the operators of Amadey
the hashes that BabbleLoader resolves at runtime and collects manually are as follows. { "0x1abec790": "NtCreateSection" "0x993c0058": "NtMapViewOfSection" "0x92263458": "NtUnmapViewOfSection" "0x9da1d253": "NtClose" "0x6af3f390": "NTQuerySystemInformation" "0xa96ab0e4": "RtlAllocateHeap" "0x8a21a480": "RtlFreeHeap" }
the sub_140001080 function creates a for loop through the entire NtDLL Export Table, and checks to identify whether the name of the API currently collected is equal to the Hash placed as an argument, through the sub_140001010 function.
the vast majority of the capabilities not mentioned above and present in the image come from BabbleLoader’s ability to contain a large amount of Junk Code, with several meaningless flows, unused strings, and which have the purpose of making it difficult for researchers or Endpoint Protection Software based on Machine Learning to analyze.
Declaration of an array (implemented via Stack String) with encoded bytes; Decode of the array bytes, through an XOR operation, using the initial XOR key 0x375b879a
Basically, both techniques have the purpose of identifying the Syscall Stub that is not Hooked, by identifying each standard opcode for the stub... if they are not exactly in the position indicated in the pseudocode, and in their place there is 0xe9 ... it means that the function is Hooked.
Basically, both techniques have the purpose of identifying the Syscall Stub that is not Hooked, by identifying each standard opcode for the stub... if they are not exactly in the position indicated in the pseudocode, and in their place there is 0xe9 ... it means that the function is Hooked.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BabbleLoader is discussed as a loader delivered through infrastructure connected to Amadey.
A malware loader focused on defense evasion. The content describes BabbleLoader as using large amounts of partially unique junk code, string decryption, manual NTDLL parsing, custom API hashing, Halo's Gate-based EDR hook evasion, and direct syscall execution to load payloads while avoiding detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.