SADBRIDGE

First seen
2022-05-01 00:00:00
Malware type
loader
Profile updated
2026-07-07 15:04:01

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

According to Elastic, SADBRIDGE is a malware loader packaged as an MSI executable for delivery and it uses DLL side-loading with various injection techniques to execute malicious payloads. SADBRIDGE abuses legitimate applications such as x64dbg.exe and MonitoringHost.exe to load malicious DLLs like x64bridge.dll and HealthServiceRuntime.dll, which leads to subsequent stages and shellcodes.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Sadbridge_Auto (yara-rule)

Reports & references

  • elastic.co — Under The Sadbridge With Gosar (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sadbridge (report)

External references