Croxloader

First seen
2022-05-10 00:00:00
Malware type
loader
Profile updated
2026-07-07 13:06:07

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications transportation-and-logistics

Targeted regions: country_code:cn country_code:us country_code:in

Context

According to Trend Micro, this is a custom loader for win.cobalt_strike, used by Earth Longzhi (a subgroup of APT41).

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Croxloader_Auto (yara-rule)

Reports & references

  • Trend Micro — Attack On Security Titans Earth Longzhi Returns With New Tricks (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Croxloader (report)

External references