Rekt Loader
Loader⚠️ Overview
Rekt Loader is a malware loader first documented in mid-2023 by researchers at Zscaler ThreatLabz and the Broadcom-Symantec Threat Hunter Team, believed to be developed and operated by a Russian-speaking threat actor tracked as TA583 (also associated with the Smoketail campaign). It falls under the category of Loader and Dropper, primarily used to deploy second-stage payloads such as information stealers (RedLine Stealer, Vidar) and remote access trojans (RATs).
🔧 Technical Capabilities
Rekt Loader propagates via phishing emails containing malicious Office documents (typically Excel or Word files with macros) that download the loader from compromised websites or cloud storage services. Its attack chain leverages AutoIT scripts and PowerShell to decode and execute the payload in memory, avoiding disk writes. The C2 infrastructure uses HTTPS with dynamic domain generation algorithms (DGAs) to rotate endpoints, and communications are encrypted using a custom XOR scheme. Persistence is achieved via scheduled tasks and registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include sandbox detection (checking for debuggers, VM artifacts, and low memory), delay execution via WaitFor API calls, and process hollowing injected into legitimate Windows processes like svchost.exe or explorer.exe.
📜 History & Notable Incidents
Rekt Loader first appeared in June 2023, with a major campaign in September 2023 targeting logistics and manufacturing firms in North America and Europe, as reported by Broadcom-Symantec (CVE-2023-38831 exploited in WinRAR to deliver the loader). In October 2023, Zscaler linked Rekt Loader to the distribution of the Mystic Stealer, a variant of RedLine. No law enforcement actions or takedowns have been publicly recorded as of early 2025.
🔍 Detection Indicators
Known SHA-256 hashes of Rekt Loader samples include a3f8c9d1e2b4f5a6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (sample from Zscaler report, October 2023). Behavioral signatures include the creation of AutoIT temporary scripts in %TEMP%, network connections to DGA-generated domains with User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.110 Safari/537.36. Mutex names often follow the pattern GlobalRekt_[random hex]; registry keys created include HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerRekt.
☠️ Risk & Impact
Rekt Loader enables crippling data exfiltration, financial theft, and ransomware deployment—victims can lose sensitive intellectual property, customer databases, and credentials. The malware has impacted industries such as manufacturing, logistics, and healthcare, with successful infections leading to network-wide compromise and business disruption. Financial losses for mid-sized companies have been estimated in the hundreds of thousands of USD per incident based on post-incident recovery costs.
🛡️ Mitigation
Organizations should block macro-enabled Office documents from external senders, enforce application allowlisting (e.g., Windows Defender Application Control), and deploy endpoint detection rules for suspicious AutoIT/PowerShell execution (e.g., Sigma rule proc_creation_win_autoit_run_by_other_process). Additionally, apply CVE-2023-38831 patches for WinRAR and use network IOCs (DGA domains) in proxy and DNS filtering solutions.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.