Vetta Loader

Aliases: BrokerLoader, EMPTYSPACE

Malware type
loader, downloader
Profile updated
2026-07-07 13:11:23

Targeted industries: technology-and-telecommunications financial-services retail-and-hospitality

Context

Vetta Loader is a persistent Loader spreading with infected USB drives. It downloads other components leveraging legit hosting services. https://yoroi.company/wp-content/uploads/2023/12/202311-Vetta-Loader_Def-min.pdf

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Apt_Unc4990_Emptyspace_Pyc (yara-rule)

Reports & references

  • Mandiant — Unc4990 Evolution Usb Malware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Vetta Loader (report)
  • yoroi.company — Unveiling Vetta Loader A Custom Loader Hitting Italy And Spread Through Infected Usb Drives (report)
  • googlecloudcommunity.com — Finding Malware Detecting Emptyspace With Google Security (report)
  • fortgale.com — Nebula Broker Offensive Operations Italy (report)

External references