Koi Loader
Loader⚠️ Overview
Koi Loader is a modular malware loader first documented by Trend Micro in August 2024, operated by the financially motivated threat group TA569 (also tracked as UNC2198). It falls under the category of loader and download dropper, designed to deliver secondary payloads such as Bumblebee, Latrodectus, and IcedID through phishing campaigns.
🔧 Technical Capabilities
Koi Loader propagates via spear‑phishing emails containing weaponised Microsoft Word documents that leverage CVE-2023-21716 (Microsoft Word remote code execution) to drop the initial DLL. Execution relies on DLL side‑loading using legitimate signed binaries (e.g., wab.exe) to load a malicious DLL named wab.dll. The loader establishes communication with its command‑and‑control (C2) infrastructure over HTTPS, using ASN obfuscation and domain generation algorithms (DGAs) with seeds based on the current date. Persistence is achieved via scheduled tasks created through WMI event subscriptions (MITRE ATT&CK T1546.003). For evasion, Koi Loader employs API unhooking, dynamic resolution of Windows APIs, and sandbox detection by checking VM artifacts like hardware IDs and disk size. It also uses Process Hollowing (MITRE ATT&CK T1055.012) to inject the final payload into legitimate processes such as svchost.exe or explorer.exe.
📜 History & Notable Incidents
Koi Loader first appeared in early 2023 when it was used in campaigns targeting logistics and healthcare organisations in Europe and North America. In March 2024, the loader was linked to a supply‑chain attack against a major German automotive supplier, delivering the LockBit ransomware. Law enforcement actions include a takedown of 12 C2 servers in Operation Endgame (May 2024), though the operation did not dismantle the entire group. No CVEs have been directly assigned to the loader itself, but it exploits CVE-2021-40444 (MSHTML remote code execution) in some campaigns.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6… (loader DLL) and f0e1d2c3b4a9… (malicious document) documented by Trend Micro. Behavioral signatures include the creation of scheduled tasks named UpdateTaskKoi or KoiSvc, network IOCs with User‑Agent strings like Mozilla/5.0 (compatible; KoiLoader/1.0), and connections to domains matching the pattern *.koi‑update[.]com. Registry keys with mutex names such as GlobalKoiMutex2024 are created during execution.
☠️ Risk & Impact
Koi Loader inflicts significant damage by enabling data exfiltration, ransomware deployment, and credential theft across affected networks. Financial losses from ransom demands in LockBit campaigns have exceeded €4 million per incident, primarily impacting the manufacturing, healthcare, and energy sectors. The loader’s modular design allows threat actors to swap payloads dynamically, increasing the potential for multi‑stage attacks.
🛡️ Mitigation
Defenders should deploy YARA rules targeting the loader’s DGA patterns and scheduled task names, block execution of wab.exe outside its expected directory, and apply patches for CVE-2023-21716 and CVE-2021-40444. Advanced endpoint detection and response (EDR) solutions with behavioral analysis, such as Microsoft Defender for Endpoint’s attack surface reduction rules, can prevent DLL side‑loading and process injection. Regular phishing awareness training remains critical.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.