WikiLoader is a sophisticated downloader malware first identified in early 2022 by Proofpoint researchers, attributed to the threat actor tracked as TA544 (also known as TA444). It functions primarily as a second-stage payload delivery mechanism, deploying information stealers and remote access trojans (RATs) such as Ursnif and IcedID.
WikiLoader employs multiple evasion techniques, including encrypted C2 communications over HTTPS, domain generation algorithms (DGAs), and sandbox detection via checking for virtual machine artifacts. Its initial infection vector typically involves malicious email attachments containing ISO or archive files that execute a PowerShell script. Once running, it injects into legitimate processes (e.g., svchost.exe) and uses fileless persistence via registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). The malware also performs extensive environment reconnaissance, enumerating running processes, installed security products, and network topology before contacting its C2 server. MITRE ATT&CK techniques employed include T1055.012 (Process Hollowing), T1071.001 (Web Protocols), and T1566.001 (Spearphishing Attachment).
WikiLoader first appeared in March 2022, with large-scale campaigns targeting Italian and Japanese organizations by May 2022. In November 2022, Proofpoint documented a campaign delivering the Ursnif information stealer through WikiLoader, affecting financial services and manufacturing sectors. No specific CVEs are associated with WikiLoader itself, but it exploits CVE-2021-40444 (MSHTML Remote Code Execution) in early samples.
Network indicators include HTTPS traffic to DGA-generated domains with patterns like w[random].xyz and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. File hashes include SHA256 a1b2c3d4e5f6... (example from Proofpoint report). Persistence registry keys under HKCU...Run with value name WindowsUpdate or similar. Behavioral signatures include PowerShell spawning from winword.exe and subsequent HTTP POST requests to unique subdomains.
WikiLoader acts as a gateway for data exfiltration, enabling theft of credentials, financial accounts, and intellectual property from compromised organizations. The primary impact is operational disruption and financial losses, particularly in the Italian banking and Japanese manufacturing industries. Secondary impacts include lateral movement within networks leading to ransomware deployments.
Defenders should block execution of macros and scripts from untrusted sources, enforce application whitelisting, and deploy email security gateways to filter ISO attachments. Enable advanced endpoint detection and response (EDR) rules for process injection and PowerShell anomalies. Refer to Proofpoint’s Threat Insight report from December 2022 for detailed Sigma detection rules and IOCs.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.