CloudEyE
Aliases: GuLoader, vbdropper
- First seen
- 2019-12-01 00:00:00
- Malware type
- downloader, loader, dropper
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:45:39
- Profile updated
- 2026-07-07 13:08:09
Context
CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored.
Detection coverage
- 7 YARA rules
Detection rules
- MALPEDIA_Win_Cloudeye_Auto (yara-rule)
- SEKOIA_Guloader_Unpacker (yara-rule)
- SEKOIA_Guloader_Unpacker_Decoded (yara-rule)
- SEKOIA_Guloader_Powershell_1 (yara-rule)
- SEKOIA_Guloader_Lnk_File (yara-rule)
- SEKOIA_Guloader_Vbscript (yara-rule)
- CAPE_Guloaderprecursor (yara-rule)
Reports & references
- Broadcom/Symantec — Bluebottle Banks Targeted Africa (report)
- Microsoft — Threat Actors Leverage Tax Season To Deploy Tax Themed Phishing Campaigns (report)
- news.sophos.com — Raticate Rats As Service With Commercial Crypter (report)
- ptsecurity.com — Steganoamor Campaign Ta558 Mass Attacking Companies And Public Institutions All Around The World (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- threatresearch.ext.hp.com — Javascript Malware Dispensing Rats Into The Wild (report)
- threatresearch.ext.hp.com — Hp Wolf Security Threat Insights Report Q3 2021 (report)
- intrinsec.com — Intrinsec 2025 Threat Report Trouble In The Air (report)
- labs.bitdefender.com — 5 Times More Coronavirus Themed Malware Reports During March (report)
- intrinsec.com — Tlp Clear 20230912 En Guloader Information Report (report)
- blog.checkpoint.com — March 2023S Most Wanted Malware New Emotet Campaign Bypasses Microsoft Blocks To Distribute Malicious Onenote Files (report)
- proofpoint.com — Coronavirus Threat Landscape Update (report)
- umbrella.cisco.com — Navigating Cybersecurity During A Pandemic Latest Malware And Threat Actors (report)
- vmray.com — Azorult Delivered By Guloader Malware Analysis Spotlight (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cloudeye (report)
- blog.malwarebytes.com — Sba Phishing Scams From Malware To Advanced Social Engineering (report)
- research.checkpoint.com — Unveiling The Shadows The Dark Alliance Between Guloader And Remcos (report)
- vmray.com — Malware Analysis Spotlight Guloader (report)
- twitter.com — 1255537954304524288 (report)
- asec.ahnlab.com — 55978 (report)
- cyberint.com — Guloader Downloaded A Look At The Latest Iteration (report)
- youtube.com — Watch (report)
- irfan-eternal.github.io — Guloader Deobfuscation Using Ghidra (report)
- youtu.be — Lt07O3Xsnjq (report)
- gi7w0rm.medium.com — Cloudeye From Lnk To Shellcode 4B5F1D6D877 (report)