KugelBlitz

Malware type
loader
Profile updated
2026-07-07 14:43:59

Context

According to Threatray, KugelBlitz is a shellcode loader discovered in late 2024. It loads shellcode into memory from a file specified via command line. If no file is specified, it defaults to run.bin.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Kugelblitz_Auto (yara-rule)

Reports & references

  • threatray.com — The Bitter End Unraveling Eight Years Of Espionage Antics Part Two (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Kugelblitz (report)

External references