DarkLoader

First seen
2019-06-15 00:00:00
Malware type
loader
Family
Malware family
Last IoC activity
2026-06-23 17:56:16
Profile updated
2026-07-07 14:56:37

Targeted industries: financial-services energy-and-utilities government-and-public-sector

Targeted regions: country_code:us country_code:ru

Context

DarkLoader is a malware framework primarily used to deliver various payloads such as information stealers and ransomware. It is notable for its ability to evade detection and is used in targeted attacks against financial and government sectors.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Darkloader_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Darkloader (report)
  • twitter.com — 1459081435361517585 (report)

External references