Overview
Loaders are the delivery truck of the malware economy: they arrive via phishing or a bundled installer, check the environment, then pull the stealer, RAT or encryptor that suits the target.\nThey rotate infrastructure constantly, so blocking one domain only lasts days.\nBecause they are the moment the intrusion becomes modular, catching the download stage stops the whole chain.
Indicators of Compromise
Signals that suggest this is present on a system.
- Short-lived domains contacted shortly after a document macro runs
- Second-stage payloads written to AppData or temp
- Base64 or packed blobs decoded in memory