Harmony Loader is a Windows reflective loader used as part of a Midas ransomware intrusion. It functioned as an in-memory loading component within a broader attack chain that also involved DLL sideloading through the legitimate DISM utility, malicious DismCore.dll payloads, obfuscated PowerShell, batch scripts, and Visual Basic Script. The intrusion showed sustained post-compromise activity, including service creation for remote execution, credential harvesting with Mimikatz, lateral movement over internal RDP, use of commercial remote-access tools, and data exfiltration prior to ransomware deployment. Harmony Loader was observed as a decrypted reflective loader during the attack, indicating a role in staging or executing payloads while reducing on-disk exposure. It is associated with a campaign targeting a technology-sector victim in late 2021 and formed one component of the tooling used by operators behind a Midas ransomware incident. The malware targets Windows environments and is best characterized as a loader used during post-exploitation and defense-evasion phases of the intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
They also orchestrated parts of the attack using Visual Basic Script and Batch files, executed using the DISM.exe utility.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named by Sophos as a potentially associated component or detection in the attack chain.
A loader or potentially unwanted component mentioned by Sophos as one of the detections associated with components of this attack.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.