Researchers tied TrickGate, a shellcode-based packer and loader active since 2016, to the delivery of a wide range of malware families including TrickBot, Emotet, REvil, Maze, Cerber, Formbook, AgentTesla, AZORult, and Cobalt Strike. Check Point said the service has persisted through frequent wrapper changes and aliases while retaining the same core shellcode components, supporting the assessment that it is a single maintained operation used by multiple threat actors. Observed activity ranged from dozens to hundreds of attacks per week, typically beginning with phishing emails carrying archives, documents, or executables that launch a shellcode loader and inject the final payload while avoiding antivirus and EDR detection.
Separate reporting from Cisco Talos described a related class of email-delivered loaders used to distribute HawkEye Reborn, Remcos, and cryptocurrency miners through malicious Office files exploiting CVE-2017-11882. The loader decrypted payloads only at runtime, hid them in PE resources, and used process hollowing into RegAsm.exe, API hashing, callback abuse, direct syscalls, and the Heaven’s Gate technique to evade monitoring under WOW64. Both reports show how long-lived loader services and packers have become shared infrastructure for cybercrime, enabling repeated delivery of stealers, RATs, and ransomware through stealthy in-memory execution and anti-analysis tradecraft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Check Point said the TrickGate operational pause ended on September 26, 2022. Activity resumed after more than three months of inactivity.
Check Point observed a more than three-month operational pause in TrickGate activity from June 13, 2022 to September 26, 2022. The interruption stood out in an otherwise long-running malware-packing service.
Check Point reported that TrickGate used CRC32 for API hashing until January 2021, after which it switched to custom hash functions. This marked a technical evolution in how the packer concealed Windows API usage.
Check Point found that TrickGate shellcodes from 2016 through 2020 showed about 90% similarity. The analysis indicated the core shellcode was continuously maintained while preserving the same building blocks.
Check Point said the TrickGate shellcode-based packer-as-a-service was initially observed in July 2016. The report identifies this as the start of a long-running operation used to conceal malware from security tools.
Check Point reported that it first observed TrickGate at the end of 2016 delivering Cerber ransomware. This tied the packer to one of the early malware families it was used to deploy.
In its 2023 report, Check Point assessed with high confidence that malware packers tracked under names including TrickGate, Emotet's packer, new loader, Loncom, and NSIS-based crypter were the same maintained service. The conclusion was supported by long-term code-similarity analysis and shared shellcode building blocks.
Cisco Talos reported an ongoing phishing-driven malware distribution campaign using a sophisticated Windows loader to deliver HawkEye Reborn, Remcos, and cryptocurrency miners. The loader used runtime decryption, process hollowing into RegAsm.exe, API hashing, CallWindowProcW abuse, and Heaven's Gate to evade detection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 351 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
2 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.