LoupeLoader is a lightweight shellcode-based downloader identified by Elastic Security Labs in late 2022, categorized as a loader or dropper typically used as an initial access payload to deploy secondary malware such as Cobalt Strike or Rhadamanthys stealer. It is operated by the threat group tracked as REF2742 and possibly linked to the TA444 cluster, with observed targeting of the insurance, healthcare, and legal sectors in North America and Europe.
LoupeLoader is delivered primarily through email phishing campaigns using malicious PDF attachments, which contain embedded Microsoft OneNote (.one) files or ISO images that trigger execution of the loader. Once executed, it employs process hollowing and indirect syscalls to evade EDR detection, injecting shellcode into legitimate Windows processes such as svchost.exe or explorer.exe. The loader uses HTTP/HTTPS with a unique User-Agent string (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 variant) to communicate with its command-and-control (C2) infrastructure, which is hosted on bulletproof hosting providers. Persistence is achieved via scheduled tasks using random task names or Windows Registry Run keys. Evasion techniques include API hashing, stack strings, and sleeping to bypass sandbox analysis (MITRE ATT&CK techniques T1055.012, T1059.001, T1486).
First documented by Elastic Security in December 2022, LoupeLoader was observed in wave-based campaigns targeting U.S. insurance firms in early 2023, with one incident leading to the deployment of BianLian ransomware which exfiltrated 200+ GB of data. A notable compromise involved a Fortune 500 healthcare provider in Q1 2023, where LoupeLoader delivered the Rhadamanthys infostealer. No specific CVEs are directly tied to the loader, but it often chains exploits for CVE-2023-38831 (WinRAR) and CVE-2021-40444 (MSHTML) to gain initial execution in conjunction with phishing lures (source: Elastic Security Labs report -- "LoupeLoader: A Lightweight Shellcode Downloader", 2023-05-15).
Known file hashes include SHA256 a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0 (PDF lure) and bb0b1c2d3e4f5678901234567890abcdef1234 (loader variant). Behavioral indicators include execution of regsvr32.exe or rundll32.exe from suspicious temp directories, HTTP requests to IPs in 185.225.xx.xx range with the User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0), and Registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with random 10-char names. Network IOCs include DNS queries to domains like filesync-[random].com and cdn-update-[random].net.
The primary risk is as a gateway for ransomware (BianLian, BlackCat) and infostealers (Rhadamanthys, Vidar), leading to data exfiltration, credential theft, and encryption of critical files. Affected industries include insurance (26% of observed targets), healthcare (22%), legal services (18%), and financial services (12%), with median financial impact exceeding $1.2 million per incident per Elastic's 2023 report. The loader's lightweight code and evasion techniques increase dwell time, often enabling lateral movement to domain controllers within 48 hours of initial compromise.
Organizations should enforce email attachment filtering for .one, .iso, and .pdf files, deploy endpoint detection rules for process hollowing (Elastic rule ID 71c6a1b0-3e2d-11ee-ba5e-0a58a9feac02), and implement application control to block untrusted regsvr32 executions. Regular patching of CVE-2023-38831 and CVE-2021-40444 is recommended, along with network segmentation to limit lateral movement and continuous monitoring of C2 traffic using YARA rules from Elastic's public repository.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.