QuantLoader

First seen
2016-12-01 00:00:00
Malware type
loader, downloader
Family
Malware family
Last IoC activity
2026-07-21 16:14:33
Profile updated
2026-07-07 13:46:02

Targeted industries: financial-services technology-and-telecommunications professional-services

Context

QuantLoader is a malware primarily used to load and execute additional malicious payloads onto infected systems. It is often sold on underground forums and used by various threat actors to facilitate distribution of different types of malware.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Quantloader_Auto (yara-rule)

Reports & references

  • cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 009 (report)
  • blog.intel471.com — A Brief History Of Ta505 (report)
  • intel471.com — A Brief History Of Ta505 (report)
  • proofpoint.com — Leaked Source Code Ammyy Admin Turned Flawedammyy Rat (report)
  • Trend Micro — Necurs Evolves To Evade Spam Detection Via Internet Shortcut File (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Quantloader (report)
  • blog.malwarebytes.com — An In Depth Malware Analysis Of Quantloader (report)
  • twitter.com — 1458973883068043264 (report)
  • malwarebreakdown.com — Malvertising Campaign Uses Rig Ek To Drop Quant Loader Which Downloads Formbook (report)

External references