Koi Loader
- Malware type
- loader
- Last IoC activity
- 2026-07-22 00:37:01
- Profile updated
- 2026-07-07 15:00:48
Context
Koi Loader is a malware primarily designed to serve as a loader for other malicious payloads. It is used to deliver various types of malware into targeted systems by cybercriminals, facilitating their entry point for further exploitation.
Detection coverage
- 4 YARA rules
Detection rules
- RUSSIANPANDA_Win_Mal_Koi_Loader (yara-rule)
- RUSSIANPANDA_Win_Mal_Koi_Loader_Decrypted (yara-rule)
- SEKOIA_Koiloader_Powershell_Reflective_Loading (yara-rule)
- SEKOIA_Koi_Koiloader (yara-rule)
Reports & references
- medium.com — Updates From The Maas New Threats Delivered Through Nullmixer D45Defc260D1 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Koiloader (report)
- esentire.com — The Long And Shortcut Of It Koiloader Analysis (report)
- esentire.com — Unraveling Not Azorult But Koi Loader A Precursor To Koi Stealer (report)