DarkLoader
- First seen
- 2019-06-15 00:00:00
- Malware type
- loader
- Family
- Malware family
- Last IoC activity
- 2026-06-23 17:56:16
- Profile updated
- 2026-07-07 14:56:37
Targeted industries: financial-services energy-and-utilities government-and-public-sector
Targeted regions: country_code:us country_code:ru
Context
DarkLoader is a malware framework primarily used to deliver various payloads such as information stealers and ransomware. It is notable for its ability to evade detection and is used in targeted attacks against financial and government sectors.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Darkloader_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Darkloader (report)
- twitter.com — 1459081435361517585 (report)