Proofpoint reported that WikiLoader, a downloader malware family active since late 2022, has been used in campaigns targeting primarily Italian organizations and was observed delivering Ursnif payloads, including samples tied to GroupID 5050. The malware was linked first to TA544 and later to TA551, indicating it is likely shared or rented across multiple cybercriminal operations rather than used by a single actor. Delivery chains included macro-enabled Excel documents, OneNote attachments with embedded executables, and PDF lures that led victims to ZIP archives containing JavaScript downloaders.
Technical analysis of a later sample showed WikiLoader relying on layered shellcode, string deobfuscation, PEB walking for API resolution, anti-hooking checks, indirect syscall preparation, and long stalling or connectivity-validation routines to evade sandboxing and endpoint defenses. The sample injected shellcode into explorer.exe, created a mutex, collected host data, base64-encoded it, and sent it to one of eight hard-coded HTTPS endpoints using a specific HTTP cookie value; it then appeared to wait for a C2 response containing a gmail tag to obtain a decryption key for an embedded payload. Researchers said these behaviors align with Proofpoint's earlier reporting that WikiLoader remains under active development, including newer variants that use HTTP-cookie-based host-information exfiltration and evolving payload-retrieval methods such as MQTT.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
On 27 February 2024, an independent malware analysis report documented a WikiLoader sample that injected shellcode into explorer.exe, performed anti-analysis checks, exfiltrated host data via HTTP cookies, and attempted to retrieve additional payload material from hard-coded HTTPS URLs. The analyst said the execution flow closely matched prior Proofpoint research but the final stage could not be recovered because the C2 infrastructure was not responding.
On 27 July 2023, Proofpoint published research describing WikiLoader as a newly identified downloader used in at least eight campaigns since December 2022. The company said it named the malware because it requests Wikipedia and checks for the string "The Free" in the response.
On 11 July 2023, TA544 used accounting-themed emails with PDF attachments that led recipients to a zipped JavaScript downloader for WikiLoader. Proofpoint said the campaign sent more than 150,000 messages and did not exclusively target Italian organizations.
IBM X-Force reported that since mid-2023 the WailingCrab malware family, also known as WikiLoader, has used the legitimate broker.emqx.io MQTT service for backdoor command-and-control. The report detailed the malware's MQTT registration, check-in, topic subscription, payload delivery, and result reporting workflow, along with DLL side-loading and storage paths used during execution.
On 31 March 2023, TA551 delivered WikiLoader through OneNote attachments containing embedded executables. Proofpoint said this was the first observed WikiLoader use by an actor other than TA544 and that the campaign targeted Italian organizations.
On 8 February 2023, TA544 spoofed an Italian courier service in a campaign using macro-enabled Excel documents. The infection chain installed WikiLoader and then Ursnif.
On 27 December 2022, TA544 ran a campaign spoofing the Italian Revenue Agency with malicious Microsoft Excel attachments. The VBA macros in those files downloaded and executed WikiLoader.
Proofpoint first identified the WikiLoader downloader malware family in December 2022. The earliest observed campaign involved TA544, which typically targets Italian organizations and uses Ursnif as a follow-on payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 70 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcesecurityintelligence.com
Open sourceproofpoint.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.