GUIDLOADER

First seen
2021-09-01 00:00:00
Malware type
loader
Family
Malware family
Last IoC activity
2026-07-20 13:00:55
Profile updated
2026-07-07 13:15:54

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:cn

Context

GUIDLOADER is a sophisticated loader malware used by threat actors to deploy additional malicious payloads on compromised systems. It often targets entities within the financial services, government, and telecommunications sectors, primarily in the United States, Russia, and China.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Guidloader_Auto (yara-rule)

Reports & references

  • elastic.co — Fragile Web Ref7707 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Guidloader (report)

External references