CoffeeLoader
- First seen
- 2024-09-01 00:00:00
- Malware type
- downloader, loader
- Family
- Malware family
- Last IoC activity
- 2026-07-07 14:25:19
- Profile updated
- 2026-07-07 14:53:56
Targeted industries: financial-services technology-and-telecommunications
Context
Zscaler ThreatLabz states that this sophisticated malware family likely originated around September 2024. The purpose of the malware is to download and execute second-stage payloads while evading detection by endpoint-based security products. The malware uses numerous techniques to bypass security solutions, including a specialized packer called Armoury that utilizes the GPU, call stack spoofing, sleep obfuscation, and the use of Windows fibers. It also contains a backup DGA and is capable of deploying Rhadamanthys shellcode. ThreatLabz has observed CoffeeLoader being distributed via SmokeLoader, and both malware families share some behavioral similarities.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Coffee Loader (report)
- zscaler.com — Coffeeloader Brew Stealthy Techniques (report)