Wslink is a previously undocumented Windows malware loader notable for operating as a server rather than a conventional client-side downloader. It runs as a Windows service, listens for inbound connections, negotiates encrypted communications, receives additional PE modules from an operator, and executes those modules directly from memory using the MemoryModule library. The loader uses an RSA-based key exchange to establish AES-256-CBC session parameters and passes the active socket, communication routines, and cryptographic material to loaded modules, enabling follow-on payloads to communicate over the existing channel.
Wslink is designed for in-memory module execution and modular post-compromise use. It can cache the most recently received encrypted module and associated identifier for reuse across connecting clients, indicating support for serving multiple sessions efficiently. Samples have been observed packed and partially protected with virtualization-based obfuscation, including a multilayer virtual-machine-based protector intended to hinder reverse engineering. Analysis has shown nested virtual machines, junk code, opaque predicates, duplicated opcodes, merged instructions, and rolling operand decryption.
A known payload associated with Wslink is WinorDLL64, a backdoor delivered through the loader’s established connection. That payload supports extensive system reconnaissance and post-exploitation activity, including system information gathering, process enumeration and management, file and directory listing, file read and write operations, secure file deletion, command execution including PowerShell, session management, and directory compression for transfer. Its functionality suggests use in hands-on follow-on operations and potentially lateral movement support.
The initial compromise vector for Wslink has not been identified. Observed victimology has been limited, with detections reported in multiple regions including Central Europe, North America, the Middle East, and confirmed victims in South Korea. Wslink itself has not been conclusively tied to a threat actor based on code, functionality, or operations alone. However, the associated WinorDLL64 backdoor has been assessed with low confidence as linked to the Lazarus Group based on victimology and overlaps with Lazarus-associated tooling. Wslink therefore appears to be a stealthy modular loader used to stage in-memory payloads for targeted intrusions on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET researchers have discovered one of the payloads of the Wslink downloader ... Wslink, which had the filename WinorLoaderDLL64.dll, is a loader for Windows binaries that, unlike other such loaders, runs as a server and executes received modules in memory.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
This virtual machine introduced several other obfuscation techniques such as junk code, encoding of virtual operands, duplication of virtual opcodes, opaque predicates, merging of virtual instructions and a nested virtual machine to further obstruct reverse engineering of the code that it protects
most of the samples are packed with MPRESS and some parts of the code are virtualized ... T1027.002 Obfuscated Files or Information: Software Packing
ESET researchers recently described Wslink, a unique and previously undocumented malicious loader that runs as a server and that features a virtual-machine-based obfuscator.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows loader/downloader that runs as a server, listens on a configured port, executes received modules directly in memory, and establishes the connection later used by the WinorDLL64 payload.
A unique Windows PE loader that runs as a service/server, listens for inbound connections, performs an RSA/AES handshake, receives encrypted modules, decrypts them, and executes them directly in memory using MemoryModule.
Previously undocumented malicious loader that runs as a server and uses an advanced multilayered virtual-machine-based obfuscator to hinder analysis and detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.