CloudEyE

Aliases: GuLoader, vbdropper

First seen
2019-12-01 00:00:00
Malware type
downloader, loader, dropper
Family
Malware family
Last IoC activity
2026-07-22 02:45:39
Profile updated
2026-07-07 13:08:09

Context

CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored.

Detection coverage

  • 7 YARA rules

Detection rules

  • MALPEDIA_Win_Cloudeye_Auto (yara-rule)
  • SEKOIA_Guloader_Unpacker (yara-rule)
  • SEKOIA_Guloader_Unpacker_Decoded (yara-rule)
  • SEKOIA_Guloader_Powershell_1 (yara-rule)
  • SEKOIA_Guloader_Lnk_File (yara-rule)
  • SEKOIA_Guloader_Vbscript (yara-rule)
  • CAPE_Guloaderprecursor (yara-rule)

Reports & references

  • Broadcom/Symantec — Bluebottle Banks Targeted Africa (report)
  • Microsoft — Threat Actors Leverage Tax Season To Deploy Tax Themed Phishing Campaigns (report)
  • news.sophos.com — Raticate Rats As Service With Commercial Crypter (report)
  • ptsecurity.com — Steganoamor Campaign Ta558 Mass Attacking Companies And Public Institutions All Around The World (report)
  • Trend Micro — Ssl Tls Technical Brief (report)
  • threatresearch.ext.hp.com — Javascript Malware Dispensing Rats Into The Wild (report)
  • threatresearch.ext.hp.com — Hp Wolf Security Threat Insights Report Q3 2021 (report)
  • intrinsec.com — Intrinsec 2025 Threat Report Trouble In The Air (report)
  • labs.bitdefender.com — 5 Times More Coronavirus Themed Malware Reports During March (report)
  • intrinsec.com — Tlp Clear 20230912 En Guloader Information Report (report)
  • blog.checkpoint.com — March 2023S Most Wanted Malware New Emotet Campaign Bypasses Microsoft Blocks To Distribute Malicious Onenote Files (report)
  • proofpoint.com — Coronavirus Threat Landscape Update (report)
  • umbrella.cisco.com — Navigating Cybersecurity During A Pandemic Latest Malware And Threat Actors (report)
  • vmray.com — Azorult Delivered By Guloader Malware Analysis Spotlight (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cloudeye (report)
  • blog.malwarebytes.com — Sba Phishing Scams From Malware To Advanced Social Engineering (report)
  • research.checkpoint.com — Unveiling The Shadows The Dark Alliance Between Guloader And Remcos (report)
  • vmray.com — Malware Analysis Spotlight Guloader (report)
  • twitter.com — 1255537954304524288 (report)
  • asec.ahnlab.com — 55978 (report)
  • cyberint.com — Guloader Downloaded A Look At The Latest Iteration (report)
  • youtube.com — Watch (report)
  • irfan-eternal.github.io — Guloader Deobfuscation Using Ghidra (report)
  • youtu.be — Lt07O3Xsnjq (report)
  • gi7w0rm.medium.com — Cloudeye From Lnk To Shellcode 4B5F1D6D877 (report)

External references