Palo Alto Networks Unit 42 reported that BunnyLoader 3.0 has expanded the capabilities of the malware-as-a-service family operated by the actor known as "Player" or "Player_Bunny", evolving from a loader and stealer into a more modular platform. The malware supports credential theft, cryptocurrency theft, clipboard hijacking, keylogging, malware delivery, and remote command execution, while the latest version adds separate stealer, clipper, keylogger, and denial-of-service modules that can be downloaded on demand through a smaller base client.
The report says the operator repeatedly retooled the malware and its infrastructure to evade detection, using packers including UPX and Themida, delivery through PureCrypter, and lures masquerading as legitimate software and games. BunnyLoader 3.0 also changed its command-and-control design to use a single gate.php endpoint, RC4-obfuscated HTTP parameters, and operator-defined URL paths, while continuing to target browser data, crypto wallets, messaging apps, VPNs, gaming platforms, files, and selected financial or authentication windows; Unit 42 published associated indicators of compromise, hashes, C2 details, and a YARA rule for detection.

Pull IOCs and campaign context straight into your stack.
12 events from the most recent confirmed update back to the earliest known activity.
The first known BunnyLoader 3.0 sample was identified on Feb. 14, 2024 by security researcher Germán Fernández from a malicious .cmd script discovered by @ViriBack. The sample used a dropper delivered via a malicious CMD file with the BunnyLoader payload embedded inside.
On Feb. 11, 2024, the threat actor announced BunnyLoader 3.0 on Telegram and claimed it had been completely redesigned and enhanced by 90%. The announcement said the payloads and modules were rewritten, the payload size was reduced, and keylogging was improved.
Threat actors used BunnyLoader in December 2023 to deliver the Meduza stealer. This demonstrated the loader's role in distributing other malware families.
In December 2023, one BunnyLoader-related infection branch dropped the PureLogs loader and then delivered the PureLogs stealer. This showed BunnyLoader-associated delivery activity branching into additional malware deployment.
In December 2023, BunnyLoader was delivered as a follow-on payload to a PureCrypter infection using a novel .NET injector. One infection branch masqueraded the malware as notepet.exe or notep.exe.
Unit 42 observed BunnyLoader command-and-control servers at 134.122.197[.]80 and 91.92.254[.]31 in December 2023. The sightings showed the operator continuing to rotate infrastructure.
Unit 42 observed BunnyLoader campaigns in November 2023 using command-and-control servers at 195.10.205[.]23 and 172.105.124[.]34. This reflected continued infrastructure changes by the operator.
In October 2023, BunnyLoader samples were delivered through a ZIP archive named Shovel Knight.zip. The archive contained a Windows executable stager for BunnyLoader 2.0.
In October 2023, the author offered a private version of BunnyLoader for $350. The operator said this version was obfuscated and regularly updated to evade antivirus detection.
Unit 42 observed BunnyLoader command-and-control infrastructure at 185.241.208[.]83 in October 2023. The malware's early infrastructure used a standardized /Bunny/ PHP endpoint structure for communications.
The BunnyLoader author, tracked as “Player” or “Player_Bunny,” initially offered BunnyLoader 1.0 on Sept. 4, 2023 for $250 lifetime access. The malware was promoted as a botnet and loader written in C/C++ with credential, cryptocurrency, and clipboard theft capabilities.
By the end of September 2023, the author had added bug fixes, antivirus evasion, more data recovery methods, extra browser paths, keylogging, and anti-analysis protections. The author released BunnyLoader 2.0 by the end of that month, and it was observed in the wild.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.