SentinelLabs reported a new ZLoader malware campaign using a stealth-focused infection chain built around signed MSI installers, malicious Google Ads redirection, and LOLBAS techniques to reduce detection. The activity primarily targeted customers of Australian and German financial institutions and used a backdoored wextract.exe binary to help stage execution while blending into legitimate Windows activity.
The malware disabled Windows Defender and UAC, established persistence through regsvr32 and registry Run keys, and delivered the final payload by hijacking threads in msiexec.exe. Researchers linked the operation to the Tim botnet, identified more than 350 recently registered command-and-control domains, and found infrastructure overlaps with other ZLoader botnets including googleaktualizacija. The Zeus-derived banking trojan remains under active development and continues to support credential theft, web injection, backdoor access, and delivery of additional malware such as ransomware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
SentinelLabs reported a new ZLoader infection chain using signed MSI installers, Google Ads redirection, LOLBAS techniques, and a backdoored wextract.exe binary to evade detection. The campaign primarily targeted customers of Australian and German financial institutions and was linked to the 'Tim' botnet with more than 350 recently registered command-and-control domains observed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.