Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SolarisLoader

59
Global rank
41 infographic chevron month
Month rank
40 infographic chevron week
Week rank
0
IOCs

SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It utilizes a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes. To remain undetected, the malware patches internal Windows monitoring interfaces and isolates the machine from security updates. Finally, it establishes a resilient three-layer persistence mechanism involving scheduled tasks, registry backups, and a watchdog component.

Loader
Type
Unknown
Origin
1 June, 2026
First seen
3 September, 2026
Last seen

How to analyze SolarisLoader with ANY.RUN

Type
Unknown
Origin
1 June, 2026
First seen
3 September, 2026
Last seen

IOCs

IP addresses
20.190.160.22
2.23.246.9
196.251.107.186
40.126.31.130
23.59.18.102
48.209.138.168
62.60.226.232
74.178.240.51
172.211.123.249
135.233.45.222
135.233.95.144
172.66.2.5
48.192.1.64
2.16.204.139
2.16.164.11
48.209.138.189
135.234.160.246
2.16.164.10
2.16.241.7
142.251.14.100
Hashes
a8bd235303668981563dfb5aae338cb802817c4060e2c199b7c84901d57b7e1e
fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
57a6b29300fac0bac416f97506b7705b65782901afb5d26351f5e40917e53fb9
1b3d6e1878afbd806dc16b15bf36ea113429b64c7597236f81c91406cf727b1c
fbacc64c19e482e225d7f9042d191345ea63af2d42d547c66c07d5ee6e01e46c
4acd7adff5c2193e7b0b9a6f8235534d67772ff3d7fa59b1215de011d7455ad9
df3934740546e59befa158654a31f97380629af8a19966e8af135a1840925fd6
14219a41f1e1b3d5a3081e8b3369f5ef05fe41bba5b9fd08b98b18bbdab1ecf3
61b64a7f826a6aeae7be82ab31b0f69af1f31a861a664a2353e98715f992b42a
a564ca03842ac237973a6f07a1c25fb5a072d8fb7424b6ac8684888377391d9a
28825ea8245e6bcd88c3b4d744e07712f905d316d7005845629b4f98b7d533b9
551111f09c239f75c1a3e9ee023ed2c4e2e3bd9c8ec77527a8f0bc92e6727e1f
265ff3e568105a01f8c6d52912715be58f550096b12332fdc86c7c4e80746323
83b3fb548b094aa66bbf9da57c4d5a49acaa76914121e90aa05fb53ab47367e0
656e39770148ec3bf1928b93163a83b67fc325bc22b244327d7fbff4f1eb651b
982eead72a720efc097bdf415d06e9b97f213d6f6ecce5b2bbef1125af1e2217
bdf4942298bd77738d50c80d53174b5c01dbb7f0e7460a15c10c6fb18a9f8b95
91cbdb753f45ed138804ddcb73c426731144e75ff1508c179bb3110f7501990f
fa447a729648caf9da7cbf60e3db9eb0d9e70411e7dee51e47f9d1477f9bdcb0
4574a15398111c257404062f40e2a04caa2327d4af1fddead63feda4ed0cb228
Domains
www.microsoft.com
watson.events.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
crl.microsoft.com
settings-win.data.microsoft.com
login.live.com
activation-v2.sls.microsoft.com
client.wns.windows.com
www.bing.com
ocsp.digicert.com
go.microsoft.com
google.com
api.edgeoffer.microsoft.com
edge-consumer-static.azureedge.net
gofile.io
xpaywalletcdn.azureedge.net
raw.githubusercontent.com
clients2.googleusercontent.com
ad.a-ads.com
URLs
http://196.251.107.186/svbia/post.php
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://196.251.107.186/acovp/post.php
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://watson.events.data.microsoft.com/telemetry.request
http://62.60.226.232/zpzp/get.php?uid=65b178c1-239c-11ed-b4aa-806e6f6e6963&idx=0&total=1&fsize=114079&enc=1&cs=114079
Last Seen at
Last Seen at

Recent blog posts

post image
Release Notes: Faster TI Investigations, Fres...
watchers 3778
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 3553
comments 0
post image
Major Cyber Attacks in August 2026: US and EU...
watchers 9196
comments 0

Key Takeaways

  • Kernel-Level Defense Dismantling: SolarisLoader utilizes a "Bring Your Own Vulnerable Driver" (BYOVD) technique, exploiting a vulnerable Safetica endpoint protection driver (CVE-2026-0828) to gain kernel-level access and forcibly terminate security processes.
  • Telemetry Blinding: The malware prevents the operating system from logging or reporting malicious activity by patching the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) in memory via direct opcode modification.
  • Resilient Triple-Layer Persistence: The infection survives standard cleanup through a combination of scheduled tasks, registry-backed backups (ICtrlData), and a watchdog process that injects code into legitimate system files like RuntimeBroker.exe.
  • ANY.RUN’s Interactive Sandbox analysis confirms that the loader utilizes a silent COM-elevation/UAC-bypass path via dllhost.exe, enabling it to gain administrative privileges without triggering user-facing notifications or consent prompts.

ANY.RUN detects SolarisLoader fast, providing a response-ready report for SOC teams ANY.RUN detects SolarisLoader fast, providing a response-ready report for SOC teams

  • Active Malware-as-a-Service (MaaS) Cycle: The loader is in active development, functioning as a primary delivery vehicle for secondary payloads such as StealC, Amadey, and REMCOS RAT.

What is SolarisLoader?

SolarisLoader is a sophisticated Malware-as-a-Service (MaaS) delivery vehicle designed to dismantle a system's security infrastructure before deploying high-risk secondary payloads. First identified in early 2026, the malware is characterized by its aggressive approach to antivirus software: rather than merely attempting to hide, it actively seeks and destroys security processes from the kernel level. While it does not typically steal data itself, it creates a "blind spot" on the infected host, clearing the way for infamous stealers and loaders like Amadey.

The malware is primarily distributed through fake software installers bundled with cracked or pirated versions of popular applications and games. This distribution strategy exploits users who are already attempting to bypass legitimate software protocols, making them less likely to question the silent background installations or administrative requests that occur during the infection chain. In some instances, the loader will even drop and execute the legitimate cracked software after the infection is complete to further reduce user suspicion.

Technical analysis reveals that SolarisLoader is a highly professional product undergoing rapid evolution. Since its emergence, researchers have tracked its maturation from version 1.2.0 to 1.8.2, observing iterative refinements in its C2 communication protocols, anti-analysis techniques, and persistence mechanisms. Its core design prioritizes persistence and stealth; it utilizes a dedicated watchdog component (often recovered via PDB paths as "Solaris") that monitors the system and automatically re-initiates the malware implant if it is terminated or deleted. By combining kernel-level exploits with telemetry patching, SolarisLoader ensures that a compromised system's own security stack reports nothing unusual even as secondary payloads are actively executed.

How SolarisLoader Threatens Businesses and Organizations

For modern enterprises, SolarisLoader’s primary threat lies in its ability to create a "permanent blind spot" on an infected workstation, ensuring that subsequent malicious activities go entirely undetected by traditional monitoring tools.

Unlike most loaders that attempt to hide from security software, SolarisLoader uses a "Bring Your Own Vulnerable Driver" (BYOVD) technique to gain kernel-level access. By exploiting CVE-2026-0828 in the Safetica endpoint protection driver, the malware achieves the same system privileges as the security software itself, allowing it to forcibly terminate Windows Defender and major third-party antivirus processes like Avast, AVG, and 360 Total Security. The malware systematically "blinds" the operating system by patching the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) directly in memory. This ensures that even if follow-on payloads execute suspicious scripts or file operations, the OS will not generate the event logs or telemetry needed for EDR (Endpoint Detection and Response) or SOC teams to flag the intrusion.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

The targeting profile of SolarisLoader is opportunistic and designed to exploit gaps in both technical controls and user behavior. While its distribution is global, specific technical markers reveal focused targeting strategies:

TI Lookup shows all the latest threat intel on Solaris Loader TI Lookup shows all the latest threat intel on Solaris Loader

  • US and EU Companies: According to ANY.RUN’s [Threat Intelligence Lookup], the majority of Solaris Loader attacks affected businesses from the United States and the European Union.
  • Organizations with Permissive Local Admin Rights: SolarisLoader relies on gaining administrative privileges to execute its most damaging stages, such as driver loading and hosts file modification. It utilizes a silent COM-elevation/UAC-bypass path via dllhost.exe, which means users running with local administrative rights can be compromised without ever seeing a permission prompt.
  • Global Enterprise Users: The malware's targeting of global suites like Avast, AVG, and ReasonLabs makes it a universal threat. Any organization relying solely on signature-based antivirus or standard Windows telemetry (AMSI/ETW) is highly vulnerable, as SolarisLoader's telemetry-blinding and BYOVD techniques are specifically designed to defeat these common defenses.
  • Secondary Infection Targets: Systems already compromised by other loaders, such as XTinyLoader or Amadey, are frequently targeted for SolarisLoader deployment, as it is often used as an intermediate stage to clear security hurdles before a final payload is delivered.

How Does SolarisLoader Function?

Detonating a SolarisLoader sample inside ANY.RUN’s Interactive Sandbox reveals a highly aggressive and multi-staged attack chain designed to neutralize system defenses before establishing a permanent foothold. By moving beyond simple file execution, the loader utilizes a series of strategic maneuvers to blind the operating system and deliver high-risk secondary payloads.

Stage 1: Initial Execution and Silent Elevation

The infection typically begins when the user executes a malicious installer, which runs from the user's Temp directory. Upon launch, the malware drops several staged components into the %TEMP% folder, including WinSysKdrv.exe, 0_1671390.exe, and 1_1675328.exe. SolarisLoader detonated inside ANY.RUN’s Interactive Sandbox SolarisLoader detonated inside ANY.RUN’s Interactive Sandbox

To gain the administrative privileges necessary for its subsequent stages without alerting the user, the loader spawns WinSysKdrv.exe through dllhost.exe (COM surrogate), a technique consistent with a silent COM-elevation/UAC-bypass path. Early in this execution phase, the sample creates the SOLARIS mutex, which acts as both an execution guard and an infection marker on the host to prevent multiple instances from running simultaneously.

SolarisLoader mutex detected by ANY.RUN’s Interactive Sandbox SolarisLoader mutex detected by ANY.RUN’s Interactive Sandbox

Stage 2: Defense Dismantling and Network Isolation

Once elevated, SolarisLoader immediately begins systematically dismantling the endpoint's security stack. The sandbox analysis highlights several critical actions:

  • Neutralizing Windows Defender: The malware disables real-time protection and modifies registry values associated with security policies and exclusion lists to prevent detection.

SolarisLoader disables MS Defender SolarisLoader disables MS Defender

  • Kernel-Level Tampering: The loader creates or modifies Windows services specifically tied to kernel-driver loading. This allows the malware to achieve defense evasion by operating at the same privilege level as the operating system's core.
  • Network Isolation: To prevent the machine from receiving updates or communicating with security telemetry servers, the malware rewrites the Windows hosts file. It redirects critical security and telemetry domains to unreachable local addresses, effectively isolating the host from external remediation.
Stage 3: Resilient Persistence and Watchdog Behavior

SolarisLoader injects itself into a legitimate process SolarisLoader injects itself into a legitimate process

SolarisLoader is engineered for maximum resilience against manual or automated cleanup. It ensures survival through two primary mechanisms:

  • Process Injection: The malware injects malicious code into legitimate system processes, specifically RuntimeBroker.exe and sihost.exe. This acts as a watchdog, where these trusted system components monitor the infection and can re-initiate the malware if it is interrupted.
  • Registry-Based Fallback: For long-term survival, it sets a login/logoff helper path in the registry as a fallback mechanism, ensuring the loader re-executes whenever a user logs into the system.

Logon-script persistence fallback via the registry Logon-script persistence fallback via the registry

Stage 4: Host Reconnaissance (Fingerprinting)

Before contacting its command-and-control (C2) infrastructure, SolarisLoader performs a thorough reconnaissance of the infected workstation to create a unique host fingerprint.

Host fingerprinting: computer name, machine GUID, languages, install date, location Host fingerprinting: computer name, machine GUID, languages, install date, location

The sandbox observed the malware harvesting the following data points: Computer name and machine GUID, Windows installation date and system location settings, Supported system languages.

Stage 5: C2 Communication and Payload Delivery

The final stage of the attack involves establishing communication with the attacker's infrastructure to fulfill its role as a loader. The sample beacons to a specific C2 endpoint at 196[.]251[.]107[.]186/api.php.

SolarisLoader’s C2 beacon SolarisLoader’s C2 beacon

Following this check-in, the loader was observed pulling additional malicious payloads, including bot_x64.exe and klr.exe, from a secondary IP address (192[.]162[.]199[.]186) that has been flagged as malicious. This confirms that SolarisLoader's ultimate goal is to serve as a delivery vehicle for further staged malicious activity.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against Solaris

Because SolarisLoader operates as an evolving Malware-as-a-Service (MaaS) with infrastructure and file names that rotate rapidly, traditional static blocklists are often insufficient for long-term protection. Security teams must shift from tracking temporary indicators to identifying the durable technical fingerprints and behavioral patterns of the operation. By leveraging ANY.RUN’s Threat Intelligence, organizations can stay ahead of these evolving campaigns.

Threat Intelligence Lookup allows analysts to pivot from a single suspicious artifact to an entire cluster of related malicious activity.

threatName:"solaris"

Threat Intelligence Lookup provides actionable SolarisLoader indicators and TTPs Threat Intelligence Lookup provides actionable SolarisLoader indicators and TTPs

TI Lookup delivers a complete context on the threat, providing rich intelligence on SolarisLoader attacks, including network indicators, mutexes, file names, as well as full sandbox sessions that demonstrate the entire execution cycle from start to finish. For organizations requiring automated, high-speed protection, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators. These feeds deliver a continuous flow of the latest C2 domains and malicious IPs directly into SIEM, SOAR, and EDR platforms. By integrating these feeds, teams can automatically block emerging malicious infrastructure, such as rotating fake-installer portals, and detect active breaches before data exfiltration occurs.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

SolarisLoader represents a strategic shift in the cybercrime landscape, moving beyond simple evasion to the systematic neutralization of the entire security stack. By combining kernel-level exploits with telemetry blinding, the malware creates an environment where secondary payloads can operate with total visibility while the operating system remains unaware of the intrusion. To combat this evolving threat, organizations must move beyond static blocklists and reactive defenses, adopting a strategy that prioritizes behavioral analysis and proactive threat intelligence. Utilizing interactive sandboxing is essential to deobfuscate the loader's multi-stage logic and identify the durable technical signals, such as unauthorized driver loading and system-level telemetry tampering, before the successful delivery of high-risk secondary infections.

Frequently Asked Questions: SolarisLoader

1. What is SolarisLoader?

SolarisLoader is a specialized malware delivery vehicle designed to gain a persistent foothold on a host, disable its security tools, and deliver secondary infections like stealers and remote access trojans. It is sold on a subscription basis, allowing various threat actors to deploy it as a primary entry point for broader campaigns.

2. How does SolarisLoader bypass traditional security software?

The malware utilizes a "Bring Your Own Vulnerable Driver" (BYOVD) technique, exploiting a documented vulnerability in a legitimate third-party driver to achieve kernel-level privileges. This gives the loader the same system permissions as the security software it is attacking, allowing it to forcibly terminate security processes and endpoint detection services.

3. Why is a "clean" security scan result not trustworthy if this malware is present?

SolarisLoader specifically patches internal monitoring interfaces, such as the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW), in memory. This "blinds" the system’s own telemetry, preventing it from logging or reporting malicious activity even if the security software remains active.

4. How can organizations use interactive sandboxing and threat intelligence to stay protected?

Interactive sandboxing is essential to expose the modular logic that evades automated scanners, allowing defenders to see how the malware escalates privileges and dismantles defenses in real-time. Proactive threat intelligence allows teams to identify stable build-chain fingerprints and block rotating C2 infrastructure before it reaches the endpoint.

5. What are the key indicators of a SolarisLoader infection?

Defenders should monitor for unauthorized redirects in the system hosts file (pointing security domains to unroutable addresses), the creation of scheduled tasks disguised as system security checks, and unauthorized additions to security exclusion lists. The presence of specific binary data in the system registry also serves as a backup for the malware's self-healing loop.

HAVE A LOOK AT

LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
CryptoWall screenshot
CryptoWall
cryptowall
CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.
Read More
ClickFix screenshot
ClickFix is a sophisticated social engineering technique that tricks users into manually executing malicious commands on their devices. It masquerades as a "quick fix" for fake technical issues, CAPTCHA verifications, or error messages, often hijacking the clipboard to paste harmful PowerShell or terminal commands. This user-assisted approach helps it bypass traditional security controls, leading to infostealers like Lumma Stealer, RATs, and other malware.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More