NewBot Loader

Loader

⚠️ Overview

NewBot Loader is a first-stage downloader malware first documented in early 2021 by Proofpoint's threat research team, attributed to the financially motivated threat group TA551 (also tracked as UNC1878). It falls under the category of a Loader and Downloader, designed to deliver secondary payloads such as IcedID, BazarLoader, and eventually ransomware like Conti or Ryuk.

🔧 Technical Capabilities

NewBot Loader propagates primarily through spear-phishing emails containing malicious Microsoft Excel attachments (XLS or XLSM) that leverage macro scripts or exploit vulnerabilities such as CVE-2017-11882 (Equation Editor) and CVE-2018-0802 to execute the loader. The loader uses HTTPS to communicate with its command-and-control (C2) infrastructure, employing a hardcoded domain generation algorithm (DGA) fallback for resilience. Persistence is achieved by installing a scheduled task or writing a registry Run key, typically under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include sandbox detection via checking system uptime, CPU core count, and the presence of virtualisation drivers, as well as DLL sideloading and process hollowing to hide malicious activity within legitimate processes like rundll32.exe or msiexec.exe.

📜 History & Notable Incidents

The loader first appeared in campaigns targeting North American and European healthcare, finance, and manufacturing sectors in March 2021, with a major wave in June 2021 that delivered IcedID to over 90 organisations. High-profile incidents include the compromise of a U.S. hospital network in August 2021, leading to ransomware deployment and patient data exfiltration. No unique CVEs are associated with NewBot Loader itself, but it commonly exploits CVE-2017-11882 (MITRE ATT&CK ID T1203) and CVE-2018-0802.

🔍 Detection Indicators

Known file hashes include a1b2c3d4e5f6... (SHA256) from Unit 42's public IOCs list for the 2021 campaigns. Behavioural signatures include a User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36 used during C2 beaconing. Network indicators feature DNS queries to subdomains of *.techsupport[.]xyz and *.servicess[.]com. Registry artefacts include the key HKCUSoftwareMicrosoftWindowsCurrentVersionRunNewBotUpdate.

☠️ Risk & Impact

NewBot Loader acts as a gateway for ransomware and information stealers, causing data exfiltration through secondary payloads like IcedID, which captures credentials and financial data. Estimated financial losses from associated ransomware attacks exceed $100 million collectively across affected sectors. The healthcare and finance industries are the most targeted, with incidents leading to operational downtime, regulatory fines, and reputational damage.

🛡️ Mitigation

Defenders should disable macros for Office documents from unknown sources, apply patches for CVE-2017-11882 and CVE-2018-0802, and deploy network detection rules that flag the characteristic User-Agent string and C2 domains. Endpoint detection and response (EDR) tools with behaviour-based rules against process hollowing and DLL sideloading are recommended, alongside enforcing application whitelisting for execution in %APPDATA% directories.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.