GuLoader

S0561

Malware.View on attack.mitre.org

About this malware

GuLoader is a file downloader that has been used since at least December 2019 to distribute a variety of remote administration tool (RAT) malware, including NETWIRE, Agent Tesla, NanoCore, FormBook, and Parallax RAT.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1055
Process Injection

GuLoader has the ability to inject shellcode into a donor processes that is started in a suspended state. GuLoader has previously used RegAsm as a donor process.

T1070.004
File Deletion

GuLoader can delete its executable from the AppData\Local\Temp directory on the compromised host.

T1071.001
Web Protocols

GuLoader can use HTTP to retrieve additional binaries.

T1102
Web Service

GuLoader has the ability to download malware from Google Drive.

T1105
Ingress Tool Transfer

GuLoader can download further malware for execution on the victim's machine.

T1106
Native API

GuLoader can use a number of different APIs for discovery and execution.

T1204.001
Malicious Link

GuLoader has relied upon users clicking on links to malicious documents.

T1204.002
Malicious File

The GuLoader executable has been retrieved via embedded macros in malicious Word documents.

T1497.001
System Checks

GuLoader has the ability to perform anti-VM and anti-sandbox checks using string hashing, the API call EnumWindows, and checking for Qemu guest agent.

T1497.003
Time Based Checks

GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID.

T1547.001
Registry Run Keys / Startup Folder

GuLoader can establish persistence via the Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1566.002
Spearphishing Link

GuLoader has been spread in phishing campaigns using malicious web links.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Medium Eli Salem GuLoader April 2021 Open source
    Salem, E. (2021, April 19). Dancing With Shellcodes: Cracking the latest version of Guloader. Retrieved July 7, 2021.
  2. Unit 42 NETWIRE April 2020 Open source
    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.