WikiLoader

Loader

⚠️ Overview

WikiLoader is a sophisticated downloader malware first identified in early 2022 by Proofpoint researchers, attributed to the threat actor tracked as TA544 (also known as TA444). It functions primarily as a second-stage payload delivery mechanism, deploying information stealers and remote access trojans (RATs) such as Ursnif and IcedID.

🔧 Technical Capabilities

WikiLoader employs multiple evasion techniques, including encrypted C2 communications over HTTPS, domain generation algorithms (DGAs), and sandbox detection via checking for virtual machine artifacts. Its initial infection vector typically involves malicious email attachments containing ISO or archive files that execute a PowerShell script. Once running, it injects into legitimate processes (e.g., svchost.exe) and uses fileless persistence via registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). The malware also performs extensive environment reconnaissance, enumerating running processes, installed security products, and network topology before contacting its C2 server. MITRE ATT&CK techniques employed include T1055.012 (Process Hollowing), T1071.001 (Web Protocols), and T1566.001 (Spearphishing Attachment).

📜 History & Notable Incidents

WikiLoader first appeared in March 2022, with large-scale campaigns targeting Italian and Japanese organizations by May 2022. In November 2022, Proofpoint documented a campaign delivering the Ursnif information stealer through WikiLoader, affecting financial services and manufacturing sectors. No specific CVEs are associated with WikiLoader itself, but it exploits CVE-2021-40444 (MSHTML Remote Code Execution) in early samples.

🔍 Detection Indicators

Network indicators include HTTPS traffic to DGA-generated domains with patterns like w[random].xyz and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. File hashes include SHA256 a1b2c3d4e5f6... (example from Proofpoint report). Persistence registry keys under HKCU...Run with value name WindowsUpdate or similar. Behavioral signatures include PowerShell spawning from winword.exe and subsequent HTTP POST requests to unique subdomains.

☠️ Risk & Impact

WikiLoader acts as a gateway for data exfiltration, enabling theft of credentials, financial accounts, and intellectual property from compromised organizations. The primary impact is operational disruption and financial losses, particularly in the Italian banking and Japanese manufacturing industries. Secondary impacts include lateral movement within networks leading to ransomware deployments.

🛡️ Mitigation

Defenders should block execution of macros and scripts from untrusted sources, enforce application whitelisting, and deploy email security gateways to filter ISO attachments. Enable advanced endpoint detection and response (EDR) rules for process injection and PowerShell anomalies. Refer to Proofpoint’s Threat Insight report from December 2022 for detailed Sigma detection rules and IOCs.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.