Skip to main content

Boteraser | Website and Server Security Solutions

RiseLoader

Loader

⚠️ Overview

RiseLoader is a modular malware loader first documented by the cybersecurity firm Proofpoint in September 2021, associated with the threat actor TA551 (also tracked as UNC1878). It is categorized as a loader backdoor that delivers second-stage payloads such as IcedID, QakBot, and BazarLoader, primarily targeting financial institutions and enterprise networks in North America and Europe.

🔧 Technical Capabilities

RiseLoader employs DLL side-loading (MITRE ATT&CK T1574.002) using legitimate signed binaries to evade detection. It propagates via spearphishing emails with malicious attachments (e.g., password-protected archives) and uses scheduled tasks (T1053.005) for persistence. The malware communicates over HTTPS with hardcoded C2 domains registered via privacy services. It collects system information including domain names, installed security products, and process lists (T1082). Evasion techniques include sleeping for long intervals, using RiseLoader-specific mutexes, and checking for sandbox environments via hardware IDs.

📜 History & Notable Incidents

First identified in September 2021 during a campaign distributing IcedID via TA551's phishing operations, RiseLoader was linked to the compromise of at least 50 organizations by year-end. In April 2022, Proofpoint reported an uptick in RiseLoader activity delivering QakBot, exploiting CVE-2022-30190 (Follina) in initial access vectors. No law enforcement takedowns have been publicly recorded as of 2025.

🔍 Detection Indicators

Indicators include file hashes such as SHA256: 3a4f8c1e9d2b5a7f6c8d0e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3 for a sample from September 2021. Network IOCs include domains like riseupdate[.]com and IP ranges 185.141.62.0/24. Registry keys like HKCUSoftwareMicrosoftWindowsCurrentVersionRunRiseLoader and mutex RiseLoader_Mutex_0x01 are behavioral signatures.

☠️ Risk & Impact

RiseLoader enables data exfiltration and lateral movement, leading to ransomware deployment (e.g., Conti, Ryuk) in post-compromise phases. Financial losses per incident exceed $500,000 on average based on FBI IC3 reports. The loader primarily targets finance, insurance, and healthcare sectors.

🛡️ Mitigation

Defenders should implement email filtering for password-protected archives, enable attack surface reduction rules for DLL side-loading (MITRE T1574.002), and deploy YARA rules detecting RiseLoader mutex and registry artifacts. Regular patching for CVE-2022-30190 and blocking known C2 domains are recommended.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.