CLAIMLOADER

Loader

⚠️ Overview

ClaimLoader is a loader malware first observed in early 2024 by researchers at eSentire and Trend Micro, operating as a downloader for second-stage payloads such as AsyncRAT and Agent Tesla. It is categorized as a Trojan loader/stealer, likely operated by a financially motivated threat actor targeting English-speaking victims via phishing campaigns.

🔧 Technical Capabilities

ClaimLoader propagates through spear-phishing emails containing weaponized Microsoft Office documents or PDFs that exploit CVE-2017-11882 (Equation Editor vulnerability) or use malicious macros. It establishes C2 communication over HTTP to hardcoded IP addresses, using encrypted JSON payloads to fetch further stages (e.g., remote access trojans). Persistence is achieved via registry Run keys or scheduled tasks. Evasion techniques include process hollowing, API unhooking, and disabling Windows Defender via PowerShell commands. The loader also performs reconnaissance by collecting system metadata and exfiltrating it to the C2 before dropping the final payload.

📜 History & Notable Incidents

First documented by eSentire in a March 2024 threat report, ClaimLoader was linked to a campaign targeting healthcare and manufacturing sectors in North America. No high-profile public victim names have been disclosed, but Trend Micro observed it in June 2024 delivering Remcos RAT. No CVEs are directly associated with ClaimLoader itself; it relies on known vulnerabilities in Office and Windows components.

🔍 Detection Indicators

Known hashes include SHA256: 3e7c2f9a... (from eSentire report), and behavioral indicators: execution of "mshta.exe" or "regsvr32.exe" from temporary folders, network connections to IPs in the 45.155.xxx range (based on Trend Micro IOCs), and creation of suspicious scheduled tasks named "ClaimUpdate". User-agent strings often mimic legitimate browsers like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". MITRE ATT&CK IDs include T1204 (User Execution), T1059 (Command and Scripting Interpreter), and T1071 (Application Layer Protocol).

☠️ Risk & Impact

ClaimLoader primarily acts as a vector for information stealers and RATs, risking theft of credentials, financial data, and intellectual property. The affected sectors—healthcare and manufacturing—face potential operational disruption and regulatory fines. Financial losses are indirect but could reach hundreds of thousands per incident due to data exfiltration and ransomware follow-ons.

🛡️ Mitigation

Organizations should patch CVE-2017-11882 and disable Office macros by default; deploy email filtering to block malicious attachments, and implement endpoint detection rules for process injection and suspicious scheduled tasks. eSentire provides Sigma rules and YARA signatures for detection (see eSentire blog, March 2024).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.