Check Point Research reported that GuLoader remains an actively developed malware downloader used to deliver commodity malware including Formbook, XLoader, Remcos, LokiBot, AgentTesla, NanoCore, NetWire, and 404Keylogger. Newer variants, particularly a VBScript-based infection chain, host encrypted shellcode and payloads on public cloud services such as Google Drive, then decrypt and execute them directly in memory to avoid dropping readable payloads to disk and to keep initial detection rates low.
The latest GuLoader samples also expand anti-analysis and evasion features. Researchers said the malware encrypts strings and payloads, obscures URLs until runtime, stores payloads in raw encrypted form without PE headers, and uses exception-driven control-flow obfuscation through access violations, trap-flag single-step exceptions, int3 breakpoints, and a vectored exception handler. The combination of cloud delivery, in-memory execution, and stronger sandbox and anti-debugging defenses has helped GuLoader remain a favored delivery mechanism for multiple malware families.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Morphisec Labs reported an active GuLoader campaign observed since April that primarily targeted U.S. law firms, as well as healthcare and investment firms. The phishing-led infection chain used PIN-protected PDF lures and staged PowerShell to fetch GuLoader shellcode from github.io and ultimately deploy Remcos RAT, and the report published associated malicious URLs and hashes.
The report described newer GuLoader versions as adding stronger anti-analysis features including sandbox evasion, anti-debugging, and exception-driven control-flow obfuscation using access violations, trap-flag single-step exceptions, and int3 breakpoints handled through a vectored exception handler. It also noted encrypted strings and payloads, runtime URL reconstruction, and storage of payloads without PE headers to bypass antivirus and cloud scanning.
Check Point Research reported that GuLoader had evolved into a cloud-based malware delivery mechanism, with newer VBScript-based variants hosting encrypted shellcode and payloads on public cloud services such as Google Drive. The analysis said the malware decrypts and executes content in memory while avoiding writing decrypted payloads to disk, helping it evade detection.
Outpost24 published research examining GuLoader's anti-virtual-machine behavior, documenting how the malware used VM-detection methods to hinder analysis and evade sandboxed environments. This represents an earlier documented stage of GuLoader's defensive tradecraft before the 2023 VBScript and cloud-hosting evolution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourceresearch.checkpoint.com
Open sourceoutpost24.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.