Koi Loader

Malware type
loader
Last IoC activity
2026-07-22 00:37:01
Profile updated
2026-07-07 15:00:48

Context

Koi Loader is a malware primarily designed to serve as a loader for other malicious payloads. It is used to deliver various types of malware into targeted systems by cybercriminals, facilitating their entry point for further exploitation.

Detection coverage

  • 4 YARA rules

Detection rules

  • RUSSIANPANDA_Win_Mal_Koi_Loader (yara-rule)
  • RUSSIANPANDA_Win_Mal_Koi_Loader_Decrypted (yara-rule)
  • SEKOIA_Koiloader_Powershell_Reflective_Loading (yara-rule)
  • SEKOIA_Koi_Koiloader (yara-rule)

Reports & references

  • medium.com — Updates From The Maas New Threats Delivered Through Nullmixer D45Defc260D1 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Koiloader (report)
  • esentire.com — The Long And Shortcut Of It Koiloader Analysis (report)
  • esentire.com — Unraveling Not Azorult But Koi Loader A Precursor To Koi Stealer (report)

External references