QuantLoader
- First seen
- 2016-12-01 00:00:00
- Malware type
- loader, downloader
- Family
- Malware family
- Last IoC activity
- 2026-07-21 16:14:33
- Profile updated
- 2026-07-07 13:46:02
Targeted industries: financial-services technology-and-telecommunications professional-services
Context
QuantLoader is a malware primarily used to load and execute additional malicious payloads onto infected systems. It is often sold on underground forums and used by various threat actors to facilitate distribution of different types of malware.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Quantloader_Auto (yara-rule)
Reports & references
- cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 009 (report)
- blog.intel471.com — A Brief History Of Ta505 (report)
- intel471.com — A Brief History Of Ta505 (report)
- proofpoint.com — Leaked Source Code Ammyy Admin Turned Flawedammyy Rat (report)
- Trend Micro — Necurs Evolves To Evade Spam Detection Via Internet Shortcut File (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Quantloader (report)
- blog.malwarebytes.com — An In Depth Malware Analysis Of Quantloader (report)
- twitter.com — 1458973883068043264 (report)
- malwarebreakdown.com — Malvertising Campaign Uses Rig Ek To Drop Quant Loader Which Downloads Formbook (report)