PicassoLoader

Malware type
loader
Family
Malware family
Profile updated
2026-07-07 12:59:37

Context

PicassoLoader is a malware loader used to distribute various malicious payloads. It acts as a conduit, facilitating the download and execution of other malware on compromised systems, often used by cybercriminals as part of larger campaigns.

Reports & references

  • socprime.com — Uac 0057 Attack Detection A Surge In Adversary Activity Distributing Picassoloader And Cobalt Strike Beacon (report)
  • socprime.com — Picassoloader And Cobalt Strike Beacon Detection Uac 0057 Aka Ghostwriter Hacking Group Attacks The Ukrainian Leading Military Educational Institution (report)
  • CERT-UA — 5098518 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Picasso Loader (report)
  • harfanglab.io — Uac 0057 Pressure Ukraine Poland (report)

External references