Malware.View on attack.mitre.org
GuLoader is a file downloader that has been used since at least December 2019 to distribute a variety of remote administration tool (RAT) malware, including NETWIRE, Agent Tesla, NanoCore, FormBook, and Parallax RAT.
| Technique | Procedure example |
|---|---|
| T1055 Process Injection |
GuLoader has the ability to inject shellcode into a donor processes that is started in a suspended state. GuLoader has previously used RegAsm as a donor process. |
| T1070.004 File Deletion |
GuLoader can delete its executable from the |
| T1071.001 Web Protocols |
GuLoader can use HTTP to retrieve additional binaries. |
| T1102 Web Service |
GuLoader has the ability to download malware from Google Drive. |
| T1105 Ingress Tool Transfer |
GuLoader can download further malware for execution on the victim's machine. |
| T1106 Native API |
GuLoader can use a number of different APIs for discovery and execution. |
| T1204.001 Malicious Link |
GuLoader has relied upon users clicking on links to malicious documents. |
| T1204.002 Malicious File |
The GuLoader executable has been retrieved via embedded macros in malicious Word documents. |
| T1497.001 System Checks |
GuLoader has the ability to perform anti-VM and anti-sandbox checks using string hashing, the API call |
| T1497.003 Time Based Checks |
GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID. |
| T1547.001 Registry Run Keys / Startup Folder |
GuLoader can establish persistence via the Registry under |
| T1566.002 Spearphishing Link |
GuLoader has been spread in phishing campaigns using malicious web links. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.