Researchers tied the DELoader malware family targeting German-speaking users to the later Zloader/Zeus Sphinx banking trojan, showing how an early loader evolved into a broader modular crimeware platform. Fortinet found DELoader creating a suspended explorer.exe, decrypting and injecting an embedded DLL, then downloading and validating an additional PE payload from command-and-control infrastructure. Exposed victim logs and code strings indicated infections concentrated in Germany and Austria, while domain registration details overlapped with infrastructure previously associated with Zeus and Marcher banking malware campaigns.
Later reverse engineering showed Zloader using layered obfuscation, process injection, encrypted configuration data, and a domain generation algorithm (DGA) that produces 20-character .com fallback domains from date-based seeds and embedded RC4 keys. Avast described Zloader 2 / Silent Night as a modular banking malware platform capable of credential theft, web injects, keylogging, screenshot capture, VNC-style remote control, cryptocurrency wallet theft, and delivery of additional payloads, with distribution through spam, fake installers, and malicious websites. Investigators also linked Zloader operations to other malware ecosystems including Raccoon Stealer and Ursnif, and noted that its botnet infrastructure became the subject of a joint Microsoft-led takedown effort.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Avast reported that version 2.0.0.0 of Zloader was spotted in mid-July 2021, marking a notable version update in the malware's evolution.
Another 2021 campaign used fake pornography sites that prompted users to download software which actually installed Zloader.
In 2021, attackers used Google AdWords to promote fake Zoom sites that delivered Zloader infections.
Avast cited the earliest Silent Night sample with version 1.0.2.0 as timestamped 4 December 2019.
A seller using the handle "Axe" advertised the ZeuS-derived banking Trojan Silent Night on the Russian underground forum exploit.in, offering subscription pricing for unique and general builds plus add-on HVNC access. The listing presented Silent Night as an actively developed malware family with banking Trojan capabilities.
One analyzed packed Zloader sample, antiamsi.bin, carried a compile timestamp of 2019-05-27 07:19:22 UTC.
The Silent Night variant of Zloader appeared in 2019 and was sold on underground markets, indicating a new branded phase of the malware's development.
A later reverse-engineering analysis stated that Zloader originally dates to May 2016, placing the malware family's origins in that month.
Fortinet reported that DELoader had surfaced by at least February 2016, marking the malware family's emergence in the wild.
Avast reported that Zloader emerged around late 2016 to early 2017 as a successor to Zeus, evolving into a modular banking malware platform.
The actor using the name "Aleksandr" had registered malicious domains by the third quarter of 2015, establishing infrastructure later linked to DELoader and earlier banking malware activity.
The Zeus malware family's source code leaked in 2011, a development later cited as part of the lineage that enabled Zeus successors such as Zloader.
Microsoft announced a joint investigation with security companies and ISACs to take down the Zloader botnet and pursued the matter in court.
A researcher analyzed Zloader's domain generation algorithm, showing it generated 20-character .com domains from a date-derived RC4-encrypted seed and documenting multiple DGA seed keys across samples.
The packed Zloader sample was detected by VirusTotal as 52/74 on 2020-04-25, with some engines labeling it as Zbot or Glupteba variants.
The unpacked Zloader sample used in the DGA analysis had a compile timestamp of 2020-04-08 18:19:58 UTC.
Researchers analyzed an unidentified malware sample circulated on Twitter, named it DELoader, and described it as a loader targeting mainly German-speaking users in Germany and Austria.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
decoded.avast.io
Open sourcejohannesbader.ch
Open sourcefortinet.com
Open sourceresources.malwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.