BATLOADER

First seen
2022-01-01 00:00:00
Malware type
downloader, loader
Family
Malware family
Profile updated
2026-07-07 13:12:29

Targeted industries: financial-services professional-services retail-and-hospitality technology-and-telecommunications

Context

According to PCrisk, BATLOADER is part of the infection chain where it is used to perform the initial compromise. This malware is used to execute payloads like Ursnif. Our team has discovered BATLOADER after executing installers for legitimate software (such as Zoom, TeamViewer Visual Studio) bundled with this malware. We have found those installers on compromised websites.

Reports & references

  • rewterz.com — Rewterz Threat Alert Widely Abused Msix App Installer Disabled By Microsoft Active Iocs (report)
  • intel471.com — Malvertising Surges To Distribute Malware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Bat Loader (report)
  • Mandiant — Seo Poisoning Batloader Atera (report)
  • medium.com — Signed Dll Campaigns As A Service 7760Ac676489 (report)
  • Trend Micro — Batloader Malware Abuses Legitimate Tools Uses Obfuscated Javasc (report)
  • esentire.com — Esentire Threat Intelligence Malware Analysis Batloader (report)
  • insight-jp.nttsecurity.com — Steelclovergoogle (report)
  • esentire.com — Batloader Continues Signed Msix App Package Abuse (report)
  • Trend Micro — Batloader Campaigns Use Pyarmor Pro For Evasion (report)
  • seqrite.com — Decoding Batloader 2 X Unmasking The Threat Of Stealthy Malware Tactics (report)
  • blogs.vmware.com — Batloader The Evasive Downloader Malware (report)
  • medium.com — Revisiting Batloader C2 Structure 52F46Ff9893A (report)
  • esentire.com — Batloader Continues To Abuse Google Search Ads To Deliver Vidar Stealer And Ursnif (report)
  • kroll.com — Hive Ransomware Technical Analysis Initial Access Discovery (report)

External references