SentinelLabs reported a new ZLoader malware campaign using a stealth-focused infection chain built around signed MSI installers, malicious Google Ads redirection, and LOLBAS techniques to reduce detection. The activity primarily targeted customers of Australian and German financial institutions and used a backdoored wextract.exe binary to help stage execution while blending into legitimate Windows activity.
The malware disabled Windows Defender and UAC, established persistence through regsvr32 and registry Run keys, and delivered the final payload by hijacking threads in msiexec.exe. Researchers linked the operation to the Tim botnet, identified more than 350 recently registered command-and-control domains, and found infrastructure overlaps with other ZLoader botnets including googleaktualizacija. The Zeus-derived banking trojan remains under active development and continues to support credential theft, web injection, backdoor access, and delivery of additional malware such as ransomware.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
SentinelLabs reported a new ZLoader infection chain using signed MSI installers, Google Ads redirection, LOLBAS techniques, and a backdoored wextract.exe binary to evade detection. The campaign primarily targeted customers of Australian and German financial institutions and was linked to the 'Tim' botnet with more than 350 recently registered command-and-control domains observed.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.