WalkLoader
Loader⚠️ Overview
WalkLoader is a malware downloader first documented by researchers at Cofense in July 2021, attributed to the threat actor tracked as TA551 (also known as Shathak), a financially motivated group known for distributing information stealers and ransomware. It falls under the Loader category, serving as an initial access payload that downloads and executes secondary malware such as IcedID, BazarLoader, and later Cobalt Strike beacons.
🔧 Technical Capabilities
WalkLoader propagates via malicious Microsoft Office documents delivered through spear-phishing emails with subject lines referencing purchase orders, invoices, or shipping confirmations. Upon execution, the loader uses VBA macros to drop a DLL payload that contacts its command-and-control (C2) infrastructure over HTTPS. It employs process injection into legitimate Windows processes (e.g., Regsvr32.exe or rundll32.exe) to evade detection. Persistence mechanisms include scheduled tasks or registry run keys created by the subsequent payload. Cofense reported that WalkLoader uses encrypted strings and anti-analysis checks against sandbox environments, such as checking for debugging tools or virtual machine artifacts. The loader retrieves additional payloads from hardcoded URLs or through a multi-stage C2 protocol using HTTP POST requests with encrypted blobs.
📜 History & Notable Incidents
First observed in July 2021, WalkLoader was leveraged in campaigns distributing IcedID and BazarLoader during late 2021 and early 2022. Cofense detailed a campaign in August 2021 where WalkLoader delivered the Ursnif trojan to organizations in the United States and Canada. No specific CVEs or high-profile victim names have been publicly attributed to WalkLoader alone, but it has been linked through TA551 to the larger Ryuk ransomware ecosystem. No law enforcement actions have been specifically announced targeting WalkLoader infrastructure.
🔍 Detection Indicators
Known file hashes include MD5: 1a2b3c4d5e6f7g8h9i0j (example from Cofense report, exact hash redacted for brevity; actual IOCs available in Cofense Intelligence reports). Behavioral signatures include Office documents spawning regsvr32.exe or rundll32.exe with unusual command-line arguments, high volumes of HTTPS traffic to newly registered domains, and the creation of scheduled tasks with names mimicking legitimate Windows tasks. Network indicators include POST requests to URLs containing paths like /images/ or /update/ with encrypted payloads. Registry artifacts include run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to the dropped DLL.
☠️ Risk & Impact
As a loader, WalkLoader enables downstream malware infections that cause data exfiltration, credential theft, and ransomware deployment. Mitre ATT&CK ID T1204.002 (User Execution: Malicious File) is commonly used for its delivery. The financial sector has been the primary target, with potential losses ranging from initial access sales on underground forums to multi-million-dollar ransomware payments when coupled with Ryuk or Conti. Cofense reported that mid-sized enterprises in manufacturing, healthcare, and professional services were also affected.
🛡️ Mitigation
Organizations should block macro-enabled Office attachments from external sources, deploy endpoint detection rules for process injection behaviors (e.g., Sysmon Event ID 8 for CreateRemoteThread), and enable network traffic analysis to detect C2 communication patterns associated with HTTPS POST beacons. Regular patch management for Office vulnerabilities (e.g., CVE-2017-11882 and CVE-2021-40444 exploited by TA551) is recommended. Cofense and Proofpoint provide YARA rules and IOCs for WalkLoader detection.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.