CoffeeLoader

First seen
2024-09-01 00:00:00
Malware type
downloader, loader
Family
Malware family
Last IoC activity
2026-07-07 14:25:19
Profile updated
2026-07-07 14:53:56

Targeted industries: financial-services technology-and-telecommunications

Context

Zscaler ThreatLabz states that this sophisticated malware family likely originated around September 2024. The purpose of the malware is to download and execute second-stage payloads while evading detection by endpoint-based security products. The malware uses numerous techniques to bypass security solutions, including a specialized packer called Armoury that utilizes the GPU, call stack spoofing, sleep obfuscation, and the use of Windows fibers. It also contains a backup DGA and is capable of deploying Rhadamanthys shellcode. ThreatLabz has observed CoffeeLoader being distributed via SmokeLoader, and both malware families share some behavioral similarities.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Coffee Loader (report)
  • zscaler.com — Coffeeloader Brew Stealthy Techniques (report)

External references