EugenLoader

Aliases: FakeBat, NUMOZYLOD, PaykLoader

First seen
2021-06-15 00:00:00
Malware type
loader
Family
Malware family
Last IoC activity
2026-07-21 21:18:25
Profile updated
2026-07-07 13:12:16

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Context

A loader written in Powershell, usually delivered packaged in MSI/MSIX files.

Detection coverage

  • 3 YARA rules

Detection rules

  • RUSSIANPANDA_Fakebat_Powershell (yara-rule)
  • SEKOIA_Loader_Fakebat_Initial_Powershell_May24 (yara-rule)
  • SEKOIA_Loader_Fakebat_Powershell_Fingerprint_May24 (yara-rule)

Reports & references

  • rewterz.com — Rewterz Threat Alert Widely Abused Msix App Installer Disabled By Microsoft Active Iocs (report)
  • googlecloudcommunity.com — 789551 (report)
  • intrinsec.com — Tlp Clear Prospero Proton66 Uncovering The Links Between Bulletproof Networks (report)
  • intrinsec.com — Prospero Proton66 Tracing Uncovering The Links Between Bulletproof Networks (report)
  • blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Eugenloader (report)
  • esentire-dot-com-assets.s3.amazonaws.com — Esentire Unraveling Batloader And Fakebat (report)
  • intel471.com — Malvertising Surges To Distribute Malware (report)
  • recordedfuture.com — Grayalpha Uses Diverse Infection Vectors Deploy Powernet Loader Netsupport Rat (report)

External references