AresLoader has been advertised as a private malware loader on the Russian-language forum XSS by a seller using the handle DarkBLUP, with access reportedly priced at $300 per month and capped at ten licenses. Researchers said the malware is marketed as legitimate-looking software that launches a decoy application while silently downloading and executing additional payloads, and can also request elevated privileges through cmd.exe before passing those rights to the delivered malware. The developers further promoted features including AES/RSA-encrypted payload support, manual code morphing, and rebuilt binaries designed to hinder signature-based detection.
Technical analysis found that AresLoader collects victim IP address and time zone data, generates a UUID, and registers with command-and-control infrastructure through a POST request carrying campaign identifiers such as an owner_token. It then downloads a benign-looking file, retrieves the malicious payload, and establishes persistence through a Registry AutoRun key. Researchers described the operation as using centralized infrastructure, with builds communicating with a single server tied to ASN AS204603 registered to Partner LLC, an environment also linked to other malicious services including a Shark stealer panel and a phishing site impersonating securespend.com.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A threat actor using the name DarkBLUP advertised the private malware loader AresLoader for sale on the Russian-language hacking forum XSS. The offering was priced at $300 per month and limited to ten licenses.
OpenAnalysis documented AresLoader's advertised features, including encrypted payload support, code morphing, and rebuilds intended to alter signatures. The analysis also identified two live panel IP addresses, 45.80.69.193 and 37.220.87.52, and published a sample SHA-256 hash associated with the loader.
Flashpoint analyzed an AresLoader sample and confirmed it collected victim IP address and time zone data, generated a UUID, registered with its C2, downloaded a decoy file, retrieved additional payloads, and established persistence via a Registry AutoRun key. The report also assessed that observed builds communicated with a centralized server hosted in Partner LLC's AS204603, which it characterized as bulletproof hosting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.