MintsLoader, a multi-stage JavaScript-to-PowerShell loader associated primarily with TAG-124/LandUpdate808 and linked downstream activity to UNC4108/TA582, is targeting energy, industrial, legal, oil-and-gas, and other organizations in the United States and Europe. The campaigns use phishing, compromised websites, fake browser updates, and ClickFix/KongTuke fake CAPTCHA lures—including abuse of Italy's PEC certified-email system—to induce execution. The loader bypasses AMSI, scores hosts for sandbox or VM indicators, and uses rotating date-seeded DGA domains to retrieve payloads while sending AsyncRAT decoys to likely analysis environments.
On selected victim systems, MintsLoader commonly deploys the fileless GhostWeaver PowerShell RAT, which uses TLS 1.0 over TCP/25658 and Gzip-compressed JSON for C2; StealC and modified BOINC clients have also been delivered. A newer variant retrieves an in-memory PowerShell stager through the legacy Finger protocol and uses Hashtable-based decoding plus a reflected, compressed .NET assembly to conceal later stages. Researchers identified active GhostWeaver C2 nodes at 178.156.128.182 and 86.107.101.93 that served a persistence installer with scheduled-task persistence, AV-aware behavior, and a CMSTPLUA UAC-bypass mechanism; defenders should prioritize detection of finger.exe spawning command interpreters, suspicious headless PowerShell tasks, AMSI-bypass activity, DGA-driven HTTP traffic, and GhostWeaver TLS on port 25658.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Live probing identified active GhostWeaver C2 nodes at 178.156.128.182 and 86.107.101.93. Both accepted beacons without validation and rapidly delivered the same 206KB persistence installer.
TRAC Labs assigned the name GhostWeaver to the fileless PowerShell RAT used as a principal MintsLoader payload.
Analysts observed a phishing campaign targeting energy, oil and gas, and legal organizations in the United States and Europe with malicious JavaScript attachments and fake “Click to verify” pages that delivered MintsLoader.
Orange Cyberdefense detected widespread MintsLoader distribution between July and October 2024 through phishing and drive-by download activity.
SocGholish/FakeUpdates activity began using MintsLoader around July 2024, including infections that installed modified BOINC clients connected to attacker-controlled infrastructure.
Insikt Group identified MintsLoader activity in a February SocGholish infection, based on Palo Alto Networks Unit 42 analysis.
Orange Cyberdefense first observed the PowerShell-based, multi-stage MintsLoader malware loader, also tracked as TAG-124, LandUpdate808, and UNC4108.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 67 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourcederp.ca
Open sourceblackpointcyber.com
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.