BaoLoader

Malware type
loader
Family
Malware family
Profile updated
2026-07-07 14:48:18

Targeted industries: professional-services technology-and-telecommunications

Context

According to Expel, the developers behind the recent AppSuite-PDF and PDF Editor campaigns have used at least 26 code-signing certificates over the last seven years to make their software appear legitimate. Due to different use of and certificate clustering, the malware is believed different from both Chromeloader and TamperedChef.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Baoloader (report)
  • expel.com — The History Of Appsuite The Certs Of The Baoloader Developer (report)

External references