BaoLoader
- Malware type
- loader
- Family
- Malware family
- Profile updated
- 2026-07-07 14:48:18
Targeted industries: professional-services technology-and-telecommunications
Context
According to Expel, the developers behind the recent AppSuite-PDF and PDF Editor campaigns have used at least 26 code-signing certificates over the last seven years to make their software appear legitimate. Due to different use of and certificate clustering, the malware is believed different from both Chromeloader and TamperedChef.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Baoloader (report)
- expel.com — The History Of Appsuite The Certs Of The Baoloader Developer (report)