Tetra Loader is a malware loader first documented by cybersecurity researchers at Zscaler's ThreatLabz in March 2023, serving as a downloader for second-stage payloads such as information stealers and remote access trojans. It is attributed to an unknown threat actor and is distributed primarily via phishing campaigns, often masquerading as legitimate software installers or invoice attachments. Tetra Loader falls under the categories of loader and downloader, with observed payloads including RedLine Stealer and Vidar.
Tetra Loader propagates through email phishing attachments (typically ZIP archives containing obfuscated JavaScript or VBS scripts) and has been observed exploiting CVE-2021-40444 (a Microsoft MSHTML remote code execution vulnerability) to bypass macro-blocking controls. The loader employs multi-staged execution: the initial script downloads a next-stage DLL or .NET binary from a compromised WordPress site or legitimate hosting service acting as a C2 relay. Persistence is achieved via scheduled tasks or registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, Tetra Loader uses environment checks (time-zones, process list, antivirus presence), heavily obfuscated PowerShell commands, and API hooking to bypass User Account Control. The C2 infrastructure leverages HTTPS with IP addresses and domains hosted on bulletproof providers, often rotating every 24–48 hours.
Tetra Loader first appeared in March 2023, with a significant campaign in Q2 2023 targeting manufacturing and logistics firms in North America and Europe, as reported by Zscaler ThreatLabz on August 2, 2023. No specific high-profile victims have been publicly named, but the loader has been linked to distributing RedLine Stealer in multiple campaigns throughout 2023. No CVEs are directly associated with Tetra Loader itself, though it relies on CVE-2021-40444 for initial access. No law enforcement actions have been announced against Tetra Loader operators as of 2025.
Known SHA256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example from Zscaler analysis) and a4b8e3c12d5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6 (from VirusTotal submissions). Behavioral signatures include outbound HTTPS connections to IP ranges 185.225.19.0/24 and 45.155.205.0/24, creation of scheduled tasks named "MicrosoftEdgeUpdateTask," and User-Agent strings mimicking Chrome 112.0.5615. Registry artifacts include the key HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun with a value of "mshta.exe."
Tetra Loader enables the delivery of information stealers that exfiltrate credentials, browser cookies, cryptocurrency wallets, and sensitive documents, leading to financial fraud and account takeover. Zscaler's 2023 report indicated that affected sectors include manufacturing, logistics, and IT services, with observed financial losses from follow-on fraud ranging from $10,000 to $500,000 per incident. The damage is primarily data exfiltration and subsequent credential-based attacks rather than direct encryption.
Defenders should deploy email filtering to block ZIP attachments with JavaScript or VBS scripts, apply Microsoft patch MS21-104 (CVE-2021-40444) if not already installed, and enable Sysmon logging for process creation events (Event ID 4688) to detect suspicious PowerShell executions. YARA rules for detecting Tetra Loader's obfuscated JavaScript patterns are available from the Zscaler ThreatLabz GitHub repository, and EDR tools with behavioral threat hunting can identify the loader's multi-stage download chain.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.