Croxloader
- First seen
- 2022-05-10 00:00:00
- Malware type
- loader
- Profile updated
- 2026-07-07 13:06:07
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications transportation-and-logistics
Targeted regions: country_code:cn country_code:us country_code:in
Context
According to Trend Micro, this is a custom loader for win.cobalt_strike, used by Earth Longzhi (a subgroup of APT41).
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Croxloader_Auto (yara-rule)
Reports & references
- Trend Micro — Attack On Security Titans Earth Longzhi Returns With New Tricks (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Croxloader (report)