GuLoader

MITRE ATT&CK: S0561 View on attack.mitre.org

Aliases: GuLoader

First seen
2019-12-01 00:00:00
Malware type
downloader, loader
Family
Malware family
Operating systems
windows
Related IoCs
3525 (3524 malicious)
Last IoC activity
2026-09-02 02:45:04
Profile updated
2026-07-07 14:53:07

Targeted industries: financial-services technology-and-telecommunications healthcare-and-pharmaceutical

Context

GuLoader is a file downloader that has been used since at least December 2019 to distribute a variety of remote administration tool (RAT) malware, including NETWIRE, Agent Tesla, NanoCore, FormBook, and Parallax RAT.

Recent IoC activity

3,526 malicious indicators in Maltiverse are attributed to GuLoader (S0561). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample BSX#24001602.exe 2026-09-02 2
file sample Walmart Purchase Order WM02082022.xlsx 2026-09-02 1
file sample 823b3f494013b6a01cb143ac8ce010325499c2c48772bc0aa1882c22f7ebe618 2026-09-02 3
file sample Kelk2013_Plus.exe 2026-09-02 1
file sample 8085c17ea9441ff19ee1d021408ce2b159bdf4d53704a9afd180e76033c74415 2026-09-02 2
file sample 7fccb9545a51bb6d40e9c78bf9bc51dc2d2a78a27b81bf1c077eaf405cbba6e9 2026-09-02 4
file sample guloader.exe 2026-09-02 2
file sample 7cf961f4872fc14492cd67bec91389d6d8dc7ef9fc75949d9bdb9c16d82cddce 2026-09-02 2
file sample Fastelavnsrisets.exe 2026-09-02 2
file sample 790e71d3ed88746fa4d2c5c15ae60a08ff70b6f6a19f78bd8a4a04101e6751b2 2026-09-02 2
file sample 794687137393fa3452031ea7f651ffcb7de52b46ee4cdd72388d19c333b14a60 2026-09-02 2
file sample 77f75d57217646debafefa81bb803dbabb9cbd67c8f99c4906ab91843e42a1b7 2026-09-02 2
file sample 02b776c6eea950061204a9fa6124ebf191d6127dda2522c5e4e07d3b95dd07fe 2026-09-02 2
file sample 7683dbf87b229a5c18546c930ccf2625f3cf8443a8deddd5c18446fd953e3cd4 2026-09-02 2
file sample 74d52b94dbe44e83459e097ea1a1d22631a78bffa24ccf8ecc5492e9af9091a2 2026-09-01 3
URL https://www.mediafire.com/file/6urm5ylq31a3s24/Odeme_makbuzu.7z/file 2026-09-01 1
file sample 7361df98c7cd1e56e0345e61cf68c1d5818d4064269f9b234511c7060e97ad9f 2026-09-01 2
file sample 70d11fed787746ce829546de720d9dd9814f9f1978312123c6923c3ea9e846a7 2026-09-01 2
file sample 6f4acfdbac861233f66afa46e67b349354826d039a367314f28f13fd7bfa5287 2026-09-01 2
file sample 6f45bd0535f4654ea024f6336cdeecbc44272c903353963a7d7a0f8d8e74a51e 2026-09-01 2

Detection coverage

  • 6 YARA rules
  • 231 Sigma rules

Malware & tools used

  • Spearphishing Link (attack-pattern)
  • Process Injection (attack-pattern)
  • System Checks (attack-pattern)
  • Native API (attack-pattern)
  • File Deletion (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Web Protocols (attack-pattern)
  • Malicious Link (attack-pattern)
  • Web Service (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Malicious File (attack-pattern)

Detection rules

  • SEKOIA_Guloader_Unpacker (yara-rule)
  • SEKOIA_Guloader_Unpacker_Decoded (yara-rule)
  • SEKOIA_Guloader_Powershell_1 (yara-rule)
  • SEKOIA_Guloader_Lnk_File (yara-rule)
  • SEKOIA_Guloader_Vbscript (yara-rule)
  • CAPE_Guloaderprecursor (yara-rule)

Reports & references

  • Palo Alto Unit 42 — Guloader Installing Netwire Rat (report)
  • elis531989.medium.com — Dancing With Shellcodes Cracking The Latest Version Of Guloader 75083Fb15Cb4 (report)
  • MITRE ATT&CK — S0561 (report)

External references