EugenLoader
Aliases: FakeBat, NUMOZYLOD, PaykLoader
- First seen
- 2021-06-15 00:00:00
- Malware type
- loader
- Family
- Malware family
- Last IoC activity
- 2026-07-21 21:18:25
- Profile updated
- 2026-07-07 13:12:16
Targeted industries: financial-services technology-and-telecommunications government-and-public-sector
Context
A loader written in Powershell, usually delivered packaged in MSI/MSIX files.
Detection coverage
- 3 YARA rules
Detection rules
- RUSSIANPANDA_Fakebat_Powershell (yara-rule)
- SEKOIA_Loader_Fakebat_Initial_Powershell_May24 (yara-rule)
- SEKOIA_Loader_Fakebat_Powershell_Fingerprint_May24 (yara-rule)
Reports & references
- rewterz.com — Rewterz Threat Alert Widely Abused Msix App Installer Disabled By Microsoft Active Iocs (report)
- googlecloudcommunity.com — 789551 (report)
- intrinsec.com — Tlp Clear Prospero Proton66 Uncovering The Links Between Bulletproof Networks (report)
- intrinsec.com — Prospero Proton66 Tracing Uncovering The Links Between Bulletproof Networks (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Eugenloader (report)
- esentire-dot-com-assets.s3.amazonaws.com — Esentire Unraveling Batloader And Fakebat (report)
- intel471.com — Malvertising Surges To Distribute Malware (report)
- recordedfuture.com — Grayalpha Uses Diverse Infection Vectors Deploy Powernet Loader Netsupport Rat (report)