Vetta Loader
Aliases: BrokerLoader, EMPTYSPACE
- Malware type
- loader, downloader
- Profile updated
- 2026-07-07 13:11:23
Targeted industries: technology-and-telecommunications financial-services retail-and-hospitality
Context
Vetta Loader is a persistent Loader spreading with infected USB drives. It downloads other components leveraging legit hosting services. https://yoroi.company/wp-content/uploads/2023/12/202311-Vetta-Loader_Def-min.pdf
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Apt_Unc4990_Emptyspace_Pyc (yara-rule)
Reports & references
- Mandiant — Unc4990 Evolution Usb Malware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Vetta Loader (report)
- yoroi.company — Unveiling Vetta Loader A Custom Loader Hitting Italy And Spread Through Infected Usb Drives (report)
- googlecloudcommunity.com — Finding Malware Detecting Emptyspace With Google Security (report)
- fortgale.com — Nebula Broker Offensive Operations Italy (report)