Researchers reported continued evolution in two prominent malware loaders used for financially motivated intrusions: SocGholish and BLISTER. Elastic said newer BLISTER variants hide malicious code inside legitimate DLLs, including VLC Media Player libraries, and add stronger evasion such as domain-based environmental keying, configurable anti-debugging, revised configuration fields, and unhooking techniques aimed at bypassing userland syscall-based EDR visibility. CloudSEK’s earlier analysis showed BLISTER using code-signed components, rundll32.exe, process hollowing, and Startup-folder persistence to deliver payloads including Raccoon Stealer, Cobalt Strike Beacon, and BitRAT, while Elastic linked more recent activity to deployment of the MYTHIC implant and to an updated SocGholish infection chain.
Red Canary reported that SocGholish also changed delivery patterns, using ZIP-delivered JavaScript with filename obfuscation and UTF-8 Cyrillic homoglyphs to evade string-based detections, while selectively delivering second-stage malware in a subset of infections. Observed follow-on activity included host reconnaissance, Python-based persistence, browser credential theft, NTLM hash harvesting through forced authentication, and in some cases reported progression to RansomHub ransomware. Separate incident reporting from ReliaQuest showed how another JavaScript-based loader, Gootloader, enabled a long-dwell intrusion that escalated from SEO-poisoning and ZIP-delivered script execution to SystemBC access, LDAP discovery, Kerberoasting, RDP lateral movement, credential dumping, and exfiltration, underscoring how modern loaders are being refined as stealthy entry points for credential theft, post-exploitation, and ransomware operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
19 events from the most recent confirmed update back to the earliest known activity.
Between mid-July and mid-September 2024, Red Canary observed an uptick in SocGholish ZIP/JS lures using homoglyph characters. During this transition period, ZIP/JS accounted for more than half of detected SocGholish activity despite being a minority of activity overall in 2024.
Red Canary reported that SocGholish began incorporating Cyrillic homoglyphs into ZIP filenames in mid-2024 to evade filename-based detections. This included lookalike-character variants of lures such as "Chrome.Update.zip" and "UpdateInstaller.zip."
Elastic reported a stream of BLISTER samples in August 2023 that deployed MYTHIC and had very low detection rates. The samples included newer variants that embedded malicious code inside legitimate libraries such as VLC Media Player DLLs.
By the end of July 2023, Elastic observed campaigns using a new BLISTER loader to target victim organizations and deploy the MYTHIC implant. The activity showed the loader being used operationally in financially motivated intrusions.
Elastic analyzed an early June 2023 BLISTER sample that appeared to be a non-production loader and displayed a message box containing the string "Test." The sample indicated active development of new BLISTER variants.
ReliaQuest responded to a May 2023 incident in which a user visited a malicious SEO-poisoned webpage, downloaded a ZIP archive, and executed a JavaScript payload that initiated a Gootloader infection. The malware established persistence with a scheduled task and contacted multiple command-and-control domains.
Red Canary reported that SocGholish had used the direct-to-JavaScript lure name "Update.js" since December 2022. This became the naming convention for its direct-delivery variant before later changes in 2024.
Trend Micro reported investigations into a campaign that used SocGholish and BLISTER loaders to deliver Cobalt Strike and prepare victim environments for LockBit ransomware. The company assessed that this activity likely began in November 2021 and said early detection prevented ransomware deployment in the investigated cases.
CloudSEK reported that code-signed BLISTER malware campaigns had been active since 15 September 2021. The loader dropped a malicious DLL executed via rundll32.exe and was used to deploy follow-on payloads for unauthorized access and data theft.
CloudSEK reported that the code-signing certificate later used to sign BLISTER malware samples was validated on 23 August 2021 and issued by Sectigo to Blist LLC using a mail.ru email address. The certificate helped the malware appear legitimate and reduce antivirus detection; Sectigo later revoked it.
Elastic Security Labs stated that BLISTER was initially discovered in 2021. This marked the first known identification of the malware loader later seen evolving in subsequent campaigns.
In early November 2024, SocGholish dropped "download.js" and returned to an "Uрdate.js" lure using a Cyrillic homoglyph character. Red Canary observed this homoglyph direct-to-JS lure exclusively for the rest of 2024 and into January 2025.
After mid-September 2024, SocGholish replaced the direct-to-JS lure name with "download.js" for the rest of September and all of October 2024. Red Canary said the change coincided with waning use of the ZIP/JS variant.
By mid-September 2024, SocGholish stopped using "Update.js" as a lure name entirely. This ended the naming convention it had used for its direct-to-JS variant since December 2022.
In August 2024, Scarlet Goldfinch changed from a ZIP/JS lure to a direct-to-JS lure using the filename "Update.js." Red Canary cited this as context for later SocGholish lure-name changes intended to distinguish the two activities.
Elastic Security Labs published analysis of updated BLISTER variants, describing new capabilities including environmental keying, configurable anti-debug timing, revised configuration fields, and process instrumentation unhooking. The researchers also released updated extraction support, YARA rules, and behavioral detections for the latest activity.
In the same Gootloader intrusion, the attacker moved laterally via RDP to three internal hosts and attempted to dump LSASS on a Stealthbits server using rundll32.exe with comsvcs.dll MiniDump. After prevention controls appeared to block the attempt, the attacker downloaded ProcDump from an external FTP server.
ReliaQuest observed that three days after Kerberoasting activity, a compromised service account was used interactively and exfiltrated additional environment information to external XML-RPC endpoints. This reflected successful follow-on use of stolen credentials.
ReliaQuest reported that 58 days after the initial compromise, the attackers began privilege escalation and post-compromise activity including LDAP discovery and Kerberoasting against service accounts and users. This marked a shift from initial access to broader credential access operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
redcanary.com
Open sourcesecurity-labs.elastic.co
Open sourcereliaquest.com
Open sourceelastic.co
Open sourcetrendmicro.com
Open sourcetrendmicro.com
Open sourcecloudsek.com
Open sourcecloudsek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.