Starloader
MITRE ATT&CK: S0188 View on attack.mitre.org
Aliases: Starloader
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-07-28 07:58:11
- Profile updated
- 2026-07-07 12:52:06
Context
Starloader is a loader component that has been observed loading Felismus and associated tools.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Starloader (S0188). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 9b30f3c425c9eb4d4bf7d6bca07b82f5f63fbcc92a43e0885b2e7613d76d7a1d | 2026-07-28 | 4 |
| file sample | 5c77081476c9f44fd00c05ed385462b8020667cac4b0609d509de2c145a5d36f_unsafe | 2025-01-03 | 2 |
Detection coverage
- 28 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
Used by threat actors
- Sowbug (threat-actor)
Reports & references
- Broadcom/Symantec — Sowbug Cyber Espionage Group Targets South American And Southeast Asian Governments (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Starloader (report)
- MITRE ATT&CK — S0188 (report)