Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

BlackMatter

146
Global rank
147 infographic chevron month
Month rank
177 infographic chevron week
Week rank
0
IOCs

BlackMatter is a ransomware strain operating as a Ransomware-as-a-Service (RaaS), designed to encrypt files, remove recovery options, and extort victims across critical industries. Emerging in 2021, it quickly became a major concern due to its ability to evade defenses, spread across networks, and cause large-scale operational disruption, forcing security teams to act against a highly destructive and persistent threat.

Ransomware
Type
Unknown
Origin
1 August, 2021
First seen
2 August, 2026
Last seen

How to analyze BlackMatter with ANY.RUN

Type
Unknown
Origin
1 August, 2021
First seen
2 August, 2026
Last seen

IOCs

IP addresses
48.209.138.189
104.16.231.132
88.221.169.205
40.126.31.131
135.233.95.135
172.211.123.248
48.192.1.65
184.86.251.8
23.59.18.102
74.178.76.128
23.11.40.157
23.48.23.166
48.209.6.48
2.21.20.137
40.126.32.74
74.179.77.204
40.126.32.138
48.209.133.15
172.211.123.249
74.178.240.51
Hashes
4094d158e3b0581ba433a46d0dce62f99d8c0fd1b50bb4d0517ddc0a4a1fde24
99653a38c445ae1d4c373ee672339fd47fd098e0d0ada5f0be70e3b2bf711d38
95e059ef72686460884b9aea5c292c22917f75d56fe737d43be440f82034f438
4eabb8a700b57032952a8ae8353b400d14a688690f92f15f9b84520e016cf5c7
e0c0a5a360482b5c5ded8fad5706c4c66f215f527851ad87b31380ef6060696e
77db69049c1c45d24a5aa88ad5cefaff181a882ff42173f5fed02ab146a37f0e
eff52743773eb550fcc6ce3efc37c85724502233b6b002a35496d828bd7b280a
8566b5963d5d83451556819c448dc35b9275adb283c5f23ae67ec166e189e263
c525ffe310c648c5d657ca60ee67a77ebdb521d224dc9cdc9be5af9933251178
93ff42e60c442559119478cca468b190bade2b030e638788c4400c01f5336958
92027423aa1dbaed6eb5ca616b675ad72640cac582c1277f6e522f996c28ac8f
41ad1a04ca27a7959579e87fbbda87c93099616a64a0e66260c983381c5570d1
2a234b5aa20c3faecf725bbb54fb33f3d94543f78fa7045408e905593e49960a
5604f629523125904909547a97f3cdb5dbfe33b39878bad77534de0c3c034387
8a9a103bc417dede9f6946d9033487c410937e1761d93c358c1600b82f0a711f
e28d4e46e5d10b5fdcf0292f91e8fd767e33473116247cd5d577e4554d7a4c0c
6306be660d87ffb2271dd5d783ee32e735a792556e0b5bd672dc0b1c206fdadc
53a969094231b9032abe4148939ce08a3a4e4b30b0459fc7d90c89f65e8dcd4a
ad0440ca6998e18f5cc917d088af3fea2c0ff0febce2b5e2b6c0f1370f6e87b1
ce48969ebebdc620f4313eba2a6b6cda568b663c09d5478fa93826d401abe674
Domains
client.wns.windows.com
slscr.update.microsoft.com
holder-rough-fotos-opt.trycloudflare.com
login.live.com
google.com
www.microsoft.com
fe3cr.delivery.mp.microsoft.com
settings-win.data.microsoft.com
www.bing.com
ocsp.digicert.com
go.microsoft.com
crl.microsoft.com
activation-v2.sls.microsoft.com
nexusrules.officeapps.live.com
oneocsp.microsoft.com
self.events.data.microsoft.com
th.bing.com
config.edge.skype.com
edgeassetservice.azureedge.net
update.googleapis.com
URLs
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/waas/featuremanagement?isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&currentbranch=vb_release&accountfirstchar=&activationchannel=retail&oemmodel=dell&flightring=retail&attrdataver=186&installlanguage=en-us&osuilocale=en-us&webexperience=1&flightingbranchname=&chassistypeid=1&osskuid=48&app=cdm&installdate=1661339444&appver=&osarchitecture=amd64&defaultuserregion=244&telemetrylevel=1&osversion=10.0.19045.4046&devicefamily=windows.desktop
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2227
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6651
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10099
comments 0

What is BlackMatter Ransomware?

BlackMatter, first identified in mid-2021, is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. It is designed to target organizations across multiple industries, including healthcare, telecommunications, finance, education, government, and other critical infrastructure, making it one of the more disruptive threats in circulation.

In contrast to opportunistic ransomware, BlackMatter is deployed strategically. Once active, it encrypts files on both local and network resources, disables recovery mechanisms, and prevents victims from restoring data without negotiating with the attackers.

The malware features advanced evasion capabilities, such as Safe Mode encryption, partial file encryption to accelerate attacks, and anti-debugging techniques. It leverages a hybrid cryptographic approach, Salsa20 for file content and RSA-1024 for session keys, to lock data securely while remaining under detection thresholds.

Since its emergence, BlackMatter has been observed in both Windows and Linux campaigns, with incidents continuing into 2025. Its operators often deliver the ransomware via phishing emails, malicious attachments, or by exploiting stolen credentials to move laterally through a network.

Attackers commonly spread BlackMatter through:

  • Phishing emails carrying malicious attachments or links
  • Compromised websites and malvertising campaigns
  • Trojanized installers posing as legitimate software
  • Exploitation of valid user credentials for lateral movement
  • Abuse of administrative tools and system utilities (e.g., PowerShell, net.exe, sc.exe)

Like other modern ransomware families, BlackMatter often disguises its processes under legitimate Windows services (such as svchost.exe) to evade detection and maintain persistence within the system.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

BlackMatter Victimology

BlackMatter ransomware campaigns were notable for targeting large enterprises and critical infrastructure rather than indiscriminate attacks on individuals. Although the group publicly claimed to avoid healthcare and government sectors, many victims still came from sensitive industries.

Typical targets included:

  • Financial services and banking institutions
  • Energy and utilities providers
  • Telecommunications and technology companies
  • Manufacturing and logistics firms
  • Educational organizations
  • Regional and local government entities

The ransomware was distributed globally, with most confirmed victims in North America, Europe, and Asia. Reported ransom demands ranged from $80,000 to $30 million, with attackers typically requiring cryptocurrency payments.

Some of the most high-profile cases included:

  • NEW Cooperative (Iowa, USA): In September 2021, BlackMatter demanded $5.9 million, disrupting agricultural operations.
  • Olympus Corporation (Japan): In the same month, the gang reportedly demanded $30 million, one of the highest known ransom figures attributed to BlackMatter.

The group struck more than 50 organizations in just four months of active operations, with an average ransom demand of $5.3 million.

Despite its short lifespan after launching in mid-2021, BlackMatter quickly built a reputation as one of the most prolific ransomware operations of its time. Following law enforcement pressure and a wave of arrests in Europe, the operators announced their shutdown in November 2021. Still, successor activity, blending tactics from DarkSide and REvil, ensured that organizations across multiple sectors continued to face derivative campaigns into 2025.

BlackMatter Typical Attack Chain

There are numerous BlackMatter ransomware samples detonated in ANY.RUN’s Interactive Sandbox and analyzed by SOC teams worldwide. Let’s walk through how a typical infection unfolds.

View analysis session with BlackMatter RAT

BlackMatter RAT analysis in Sandbox

BlackMatter RAT analyzed inside ANY.RUN sandbox

Once executed, BlackMatter begins with a system check, creates the mutex Global\SystemUpdate_svchost.exe, copies itself into a new directory, and registers for autorun to ensure persistence. It then bypasses UAC, escalates privileges, and modifies the PowerShell execution policy to allow malicious commands to run without restriction.

Next comes the destructive preparation stage. The ransomware deletes shadow copies and backups (vssadmin, wbadmin), disables the Windows Recovery Environment (reagentc), and modifies boot configuration settings (bcdedit) to prevent recovery. In parallel threads, it uses net.exe and sc.exe to stop critical services and applications such as antivirus software, SQL databases, and backup tools, clearing the way for uninterrupted encryption.

BlackMatter TTPs analysis in Sandbox

Relevant TTPs displayed inside ANY.RUN sandbox

Finally, BlackMatter scans local and network drives, encrypts files with its own extension, and drops ransom notes with payment instructions in every affected directory. It also replaces the victim’s desktop background with a warning message, pointing to the ransom note for further details.

BlackMatter ransom note in SandboxRansom note displayed inside ANY.RUN’s sandbox

What BlackMatter Can Do to a System

Once deployed, BlackMatter executes a destructive sequence designed to ensure full control and maximum damage. Its capabilities include:

  • Stealth and Masquerading: Runs malicious components under svchost.exe to disguise activity and creates a unique mutex (Global\SystemUpdate_svchost.exe) to prevent multiple instances.
  • System Reconnaissance: Collects system details such as computer name, Machine GUID, Windows installation date, and language settings. It also retrieves browser security parameters to understand the environment.

BlackMatter system info discovery

System information discovery, including computer name, Machine GUID and language settings

  • Privilege Escalation: Bypasses UAC using fodhelper.exe and modifies registry keys to execute with elevated privileges. It also forces PowerShell execution policy to Bypass, ensuring malicious scripts can run unhindered.
  • Persistence: Adds itself to autorun via registry keys and creates scheduled tasks with elevated rights, allowing the ransomware to survive reboots and maintain long-term access.

BlackMatter scheduled task creation

Creation of scheduled task exposed inside ANY.RUN sandbox

  • Recovery Elimination: Deletes shadow copies with vssadmin.exe, removes backups via wbadmin.exe, disables Windows Recovery Environment using reagentc.exe, and alters boot settings with bcdedit.exe to block system restoration.
  • Service and Network Control: Uses sc.exe and net.exe to terminate antivirus tools, databases, and critical services, while probing proxy settings and network shares to prepare for lateral movement.

BlackMatter service control in Sandbox

Sc.exe and net.exe used for service control

  • Scripted Automation: Runs malicious .bat files and leverages timeout.exe to synchronize operations and evade heuristic defenses.

BlackMatter malicious files in Sandbox

Malicious .bat files visible inside ANY.RUN’s sandbox

  • Encryption: Finally, BlackMatter encrypts local and network files, appends its custom extension, and drops ransom notes in each affected directory, ensuring victims are aware that restoration is impossible without paying.

How BlackMatter Functions

BlackMatter is built for speed and disruption rather than long-term control. Its architecture combines:

  • Pre-encryption sabotage, where backup tools and recovery features are disabled to ensure data cannot be restored.
  • Fast encryption logic, using Salsa20 for file content and RSA-1024 for keys, with partial file encryption to lock large volumes quickly.
  • Victim communication infrastructure, where ransom notes direct organizations to attacker-controlled portals for negotiation and payment.

This streamlined design allows attackers to cripple organizations in a short window of access, leaving defenders with almost no opportunity to intervene once execution begins.

How BlackMatter Threatens Businesses and Organizations

For organizations, BlackMatter ransomware poses a severe threat that extends far beyond the encryption of individual files. Its design ensures maximum operational disruption, financial loss, and reputational damage.

  1. Complete Data Inaccessibility: BlackMatter encrypts both local and network resources while simultaneously removing recovery options like shadow copies and backups. This ensures organizations face a sudden and total loss of access to business-critical data.
  2. Rapid Spread Across Infrastructure: Because it can leverage administrative tools (net.exe, sc.exe) and stolen credentials, BlackMatter often moves laterally within networks. This allows attackers to cripple not just a single endpoint but entire domains, file servers, and NAS devices.
  3. Critical Service Shutdowns: By stopping antivirus engines, SQL databases, and other core services, the ransomware halts operational systems that businesses depend on daily, from transaction processing to logistics management.
  4. High-Value Extortion: With ransom demands ranging from $80,000 to $30 million, BlackMatter has directly targeted enterprises with high revenues and valuable data. This level of financial pressure, combined with the threat of leaked stolen files, forces executives into making urgent, high-stakes decisions.
  5. Sector-Specific Impact: Attacks against agriculture (e.g., NEW Cooperative in 2021) and healthcare technology (e.g., Olympus) demonstrated that ransomware is not just an IT problem, it can disrupt food supply chains, delay medical services, and destabilize critical infrastructure.
  6. Long-Term Business Consequences: Even after restoration, organizations may face weeks of downtime, lost contracts, reputational damage, and regulatory scrutiny. In some cases, disruption caused by ransomware like BlackMatter can threaten the long-term viability of smaller businesses.

Gathering Threat Intelligence on BlackMatter

Integrating threat intelligence into security operations is essential for detecting and mitigating BlackMatter attacks. Threat intelligence provides fresh indicators of compromise (IOCs), such as malicious IP addresses, domains, and file hashes, that can be used to block command-and-control infrastructure and monitor for early signs of compromise.

It also supports proactive threat hunting, enabling SOC teams to look for BlackMatter’s presence before encryption begins. Detection can rely on known behaviors, including registry modifications for persistence, use of tools like vssadmin and bcdedit for recovery elimination, and service control via sc.exe and net.exe.

Start gathering IOCs and behavioral data with the malware name search request to Threat Intelligence Lookup:

threatName:"Blackmatter"

BlackMatter samples in TI Lookup BlackMatter ransomware samples found via TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

BlackMatter highlights how ransomware groups now operate like professional businesses, capable of paralyzing entire organizations in hours. By wiping recovery options, halting services, and demanding multimillion-dollar ransoms, it forces executives, IT teams, and SOC analysts into crisis mode.

For security leaders, this means preparing not just technically but organizationally: ensuring SOC teams can spot ransomware behaviors early, aligning with legal and communications teams for incident response, and protecting brand trust when critical services are disrupted.

Staying ahead requires threat intelligence that goes beyond file signatures; context on attacker tactics, visibility into live campaigns, and shared IOCs that teams can act on quickly.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

FatalRAT screenshot
FatalRAT
fatalrat
FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.
Read More
MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More
Tycoon 2FA screenshot
Tycoon 2FA
tycoon
Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.
Read More
Cephalus screenshot
Cephalus
cephalus
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More