GuLoader
MITRE ATT&CK: S0561 View on attack.mitre.org
Aliases: GuLoader
- First seen
- 2019-12-01 00:00:00
- Malware type
- downloader, loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 3525 (3524 malicious)
- Last IoC activity
- 2026-09-02 02:45:04
- Profile updated
- 2026-07-07 14:53:07
Targeted industries: financial-services technology-and-telecommunications healthcare-and-pharmaceutical
Context
GuLoader is a file downloader that has been used since at least December 2019 to distribute a variety of remote administration tool (RAT) malware, including NETWIRE, Agent Tesla, NanoCore, FormBook, and Parallax RAT.
Recent IoC activity
3,526 malicious indicators in Maltiverse are attributed to GuLoader (S0561). The 20 most recently updated:
Detection coverage
- 6 YARA rules
- 231 Sigma rules
Malware & tools used
- Spearphishing Link (attack-pattern)
- Process Injection (attack-pattern)
- System Checks (attack-pattern)
- Native API (attack-pattern)
- File Deletion (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Web Protocols (attack-pattern)
- Malicious Link (attack-pattern)
- Web Service (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Time Based Checks (attack-pattern)
- Malicious File (attack-pattern)
Detection rules
- SEKOIA_Guloader_Unpacker (yara-rule)
- SEKOIA_Guloader_Unpacker_Decoded (yara-rule)
- SEKOIA_Guloader_Powershell_1 (yara-rule)
- SEKOIA_Guloader_Lnk_File (yara-rule)
- SEKOIA_Guloader_Vbscript (yara-rule)
- CAPE_Guloaderprecursor (yara-rule)
Reports & references
- Palo Alto Unit 42 — Guloader Installing Netwire Rat (report)
- elis531989.medium.com — Dancing With Shellcodes Cracking The Latest Version Of Guloader 75083Fb15Cb4 (report)
- MITRE ATT&CK — S0561 (report)