MintsLoader
- First seen
- 2023-02-01 00:00:00
- Malware type
- loader, rat, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:31:25
- Profile updated
- 2026-07-07 13:16:12
Targeted regions: country_code:es country_code:it country_code:pl
Context
According to Orange Cyberdefense, MintsLoader is a little-known, multi-stage malware loader that has been used since at least February 2023. It has been observed in widespread distribution campaigns between July and October 2024. The name comes from a very characteristic use of an URL parameter “1.php?s=mintsXX" (with XX being numbers). MintsLoader primarily delivers malicious RAT or infostealing payloads such as AsyncRAT and Vidar through phishing emails, targeting organizations in Europe (Spain, Italy, Poland, etc.). Written in JavaScript and PowerShell, MintsLoader operates through a multi-step infection process involving several URLs and domains, most of which use a domain generation algorithm (DGA) with .top TLD.
Detection coverage
- 1 YARA rules
Detection rules
- RUSSIANPANDA_Mintsloader (yara-rule)
Reports & references
- recordedfuture.com — Uncovering Mintsloader With Recorded Future Malware Intelligence Hunting (report)
- go.recordedfuture.com — Cta 2025 0130 (report)
- silentpush.com — Socgholish (report)
- huntress.com — Fake Browser Updates Lead To Boinc Volunteer Computing Software (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Mints Loader (report)
- x.com — 1849392561024065779 (report)
- blackpointcyber.com — Mintsloader Finger Protocol Hashtable Obfuscation (report)
- esentire.com — Mintsloader Stealc And Boinc Delivery (report)
- spamhaus.org — Pec Invoice Scam (report)
- youtube.com — Watch (report)
- youtube.com — Watch (report)
- cybersecurity.att.com — Asyncrat Loader Obfuscation Dgas Decoys And Govno (report)
- nikhilh-20.github.io — Deob Js Ast (report)
- github.com — Mintsloader (report)