NimzaLoader is a Windows malware loader associated with the TA800 threat group and used to establish an initial foothold in enterprise environments. It emerged in 2021 in phishing campaigns that used personalized lures and fake PDF-preview links to drive victims to download a disguised executable. Delivery chains have included intermediary landing pages before the final payload download, and the malware has been observed masquerading as a document to improve execution rates.
NimzaLoader is written in the Nim programming language and has been assessed as distinct from BazaLoader despite early public speculation linking the two. Reported differentiators include its implementation language, obfuscation approach, string decryption, API hashing, command-and-control response decryption, lack of domain generation algorithm use, and JSON-based communications. The malware stores many strings in encrypted form, includes an execution expiration mechanism, and uses a heartbeat capability to refresh that expiration in memory.
For command and control, NimzaLoader uses HTTPS and performs an initial handshake to exchange keying material and retrieve configuration data. Subsequent communications use encrypted JSON messages. Supported tasking includes execution of system shell and PowerShell commands, as well as delivery and injection of shellcode into a specified process, indicating a role in staging follow-on payloads and post-compromise activity. NimzaLoader has been reported as commonly followed by Cobalt Strike deployment, consistent with its use as an access-enablement loader rather than as a full-featured end-stage implant.
The malware is primarily associated with phishing-led intrusion activity against enterprise targets. Its operational role is to provide initial access, execute operator commands, and facilitate secondary payload delivery while using obfuscation and encrypted communications to hinder detection and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On February 3rd, 2021, Proofpoint observed a TA800 campaign distributing NimzaLoader... Conclusion NimzaLoader is a new initial access malware being distributed and used by the TA800 threat actor.
The latest version is written in Nim, a relatively new language utilized by threat actors the past two years, most notably by the NimzaLoader variant of BazarLoader used by the TrickBot group.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Most of the strings used by the malware are encrypted when stored by using an XOR-based algorithm and a single key per string.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Nim-based variant of BazarLoader mentioned as a comparison point for threat actors using the Nim programming language.
A loader written in Nim and used for initial access and foothold establishment in enterprise networks. It uses JSON for storage, memory management, and C2 communication, is delivered via personalized phishing links, leverages cmd.exe and powershell.exe to inject shellcode, maintains an in-memory heartbeat/expiration mechanism, and commonly delivers a second-stage Cobalt Strike payload.
A distinct malware family written in Nim and used as initial access malware. It communicates over HTTPS with C2 infrastructure, performs a key exchange, receives JSON-formatted tasks, and supports commands to execute cmd.exe and PowerShell commands, inject shellcode into a process, redo handshakes, and update its in-memory expiration time. The report also notes evidence it may deliver Cobalt Strike as a secondary payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.