SADBRIDGE
- First seen
- 2022-05-01 00:00:00
- Malware type
- loader
- Profile updated
- 2026-07-07 15:04:01
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
According to Elastic, SADBRIDGE is a malware loader packaged as an MSI executable for delivery and it uses DLL side-loading with various injection techniques to execute malicious payloads. SADBRIDGE abuses legitimate applications such as x64dbg.exe and MonitoringHost.exe to load malicious DLLs like x64bridge.dll and HealthServiceRuntime.dll, which leads to subsequent stages and shellcodes.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Sadbridge_Auto (yara-rule)
Reports & references
- elastic.co — Under The Sadbridge With Gosar (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sadbridge (report)