Zloader, a ZeuS-derived banking trojan that steals browser data, cookies, passwords, screenshots, and other host information, was used in multiple campaigns that combined layered delivery chains with strong evasion and persistence. Researchers documented malspam operations using MHTML attachments, password-protected XLS files, VBA and XLM macros, and rundll32.exe, as well as a later campaign that used the legitimate RMM tool Atera for initial access. In that operation, attackers weakened Microsoft Defender, disabled investigation tools, and abused a weakness in Microsoft Authenticode by appending malicious script content to Microsoft-signed DLLs while preserving a seemingly valid signature, then launching the script with mshta.exe and executing Zloader through regsvr32.exe. Across samples, Zloader commonly injected its core payload into a suspended msiexec.exe process, stored encrypted configuration data, and maintained persistence through Startup-folder scripts and Windows Run keys.
Technical analyses showed Zloader evolving into a modular malware platform with anti-analysis features including encrypted strings, runtime API resolution, filename checks, process injection, and heavy API hammering that can generate more than a million file or registry-related calls before payload execution. Newer variants retained RC4-encrypted configuration data but added revised domain-generation logic and network protections using RSA, RC4, and Zeus BinStorage-style encryption over HTTP POST. Microsoft, ESET, Lumen Black Lotus Labs, Palo Alto Networks Unit 42, and others later disrupted three Zloader botnets by seizing 65 active command-and-control domains and 319 DGA-generated domains, while reporting that the malware had been tracked since 2019 across roughly 14,000 unique samples and more than 1,300 C2 servers, with some affiliates tied to DarkSide ransomware, Cobalt Strike, Raccoon infostealer, and large victim populations in North America.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
25 events from the most recent confirmed update back to the earliest known activity.
ESET reported that Microsoft's investigation identified Denis Malikov as a co-author of a malicious component used by operators of one of the disrupted Zloader botnets.
ESET said the disruption operation also took over 319 already registered DGA-generated domains and pursued measures to block future Zloader DGA registrations.
Microsoft, ESET, Black Lotus Labs, Palo Alto Networks Unit 42, and others carried out a coordinated disruption of three Zloader botnets by taking over 65 recently used command-and-control domains.
As of January 2, 2022, Check Point observed 2,170 unique victim IPs downloading the malicious DLL in the Authenticode-abuse Zloader campaign, with most victims in the United States and Canada.
On December 10, a user at a U.S. automotive company downloaded a trojanized TeamViewer MSI after clicking a malicious ad, leading to Zloader infection. Sophos said the intrusion used CVE-2013-3900 and mshta.exe to execute follow-on payloads, including Atera Agent and a Cobalt Strike beacon, before the incident was contained to one workstation.
ESET reported that the major affiliate associated with RC4 key dh8f3@3hdf#hsf23 remained active until late November 2021.
Check Point reported that a new Zloader campaign was first observed in early November 2021, using Atera for initial access and abusing Microsoft Authenticode verification by appending script content to signed DLLs.
SentinelOne reported a new Zloader infection chain featuring improved stealth and evasion mechanisms. The report documented a distinct technical evolution in how Zloader was being delivered and executed.
ESET said it observed Zloader version 2.0 samples compiled in July 2021, but assessed them as test builds rather than mature operational malware.
By June 2021, researchers documented a Zloader delivery campaign that used a fake porn website and bogus Java plug-in installer to infect users. The chain used j_service.exe and AccessibleHandler.dll, performed locale and anti-debugging checks, downloaded an encrypted payload from vivacemusic[.]site, and executed the final Zloader DLL with regsvr32.exe.
Researchers described campaigns running from May through December 2021 that used fake installers and Microsoft-signed DLL polyglots executed via mshta.exe to decrypt and launch payloads including Zloader, Gozi, AteraAgent, and Cobalt Strike. The report linked the operation to ConfCrew and documented selective enterprise targeting, Defender tampering, and supporting infrastructure.
Hornetsecurity reported that on February 15, 2021, most observed Zloader MHTML emails were destined for Canadian recipients, indicating a concentration of targeting in that wave.
ESET observed Zloader activity decline during 2021, leaving only a small number of actors actively using the malware.
Hornetsecurity observed a Zloader campaign starting in January 2021 that used MHTML attachments disguised as Word documents to deliver password-protected XLS files and ultimately execute Zloader.
Hornetsecurity noted that the downloaded Zloader samples in its campaign analysis were tied to the "kev" botnet configuration tag, which had been publicly observed since December 2020.
On 2020-10-21, ESTsecurity reported a ZLoader campaign in South Korea using phishing emails that warned recipients their business would soon be suspended. The chain redirected victims through a Google document to download an Excel 4.0 macro file that fetched and executed a ZLoader DLL via rundll32.exe.
ESET reported that a major affiliate identified by RC4 key dh8f3@3hdf#hsf23 was active from June 2020 and used spam-delivered Zloader infections to deploy additional payloads including DarkSide ransomware.
ESET said Zloader implemented a DGA that generated fallback domains for command-and-control, helping researchers discover about 300 additional active domains used by operators.
On December 6, 2019, Proofpoint observed an invoice-themed email campaign delivering ZLoader version 1.0.2.0 via a malicious Word document linked from a PDF attachment. The campaign used Keitaro TDS to filter downloads and hinder automated analysis, marking an early observed distribution of the re-emerged variant.
LAC reported that Zloader version 1.0-series samples targeting Japanese financial institution accounts were observed in late December 2019. The report assessed that the threat actor likely began targeting Japan around that time, using exploit kits tied to malicious web advertisements as one infection path.
ESET reported that the first Zloader version it identified was version 1.0.0.0, compiled and advertised on underground forums as Silent Night.
The VinCSS analysis states that Zloader was first discovered in 2016 as a banking trojan also known as Terdot.
The source content states that the ZeuS malware source code was made public, providing the codebase from which Zloader is said to have been built.
Unit 42 reported that analyzed Zloader samples used API Hammering through four large functions and nested file I/O calls, generating more than one million API calls before payload injection to evade sandbox detection.
Check Point linked the Authenticode-abuse Zloader campaign to the cybercriminal group MalSmoke based on infrastructure and tradecraft overlaps.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcezscaler.com
Open sourceunit42.paloaltonetworks.com
Open sourcemicrosoft.com
Open sourceblog.alyac.co.kr
Open sourceproofpoint.com
Open sourceblog.malwarebytes.com
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.