Zloader
Loader⚠️ Overview
ZLoader is a modular banking trojan and loader malware first identified in January 2020 by Check Point Research, descending from the Zeus crimeware kit (also known as Zbot). It is operated by a financially motivated threat cluster tracked as TA544, commonly used as a payload delivery vehicle for ransomware such as Conti and Ryuk. Zloader belongs to the Trojan/Downloader category and is primarily seen in North American and European campaigns targeting financial institutions.
🔧 Technical Capabilities
Zloader propagates via malicious email attachments (typically Excel add-ins with VBA macros) and drive-by downloads from compromised websites. Its attack vector involves initial access through phishing emails containing weaponised documents that drop a DLL loader. The malware uses encrypted C2 communication over HTTPS and relies on a certificate-pinning technique to avoid interception. Persistence is maintained by installing itself as a scheduled task or registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, Zloader checks for sandbox environments by verifying mouse movement patterns and window titles, and it frequently updates its C2 domains using domain generation algorithms (DGAs). It can inject code into legitimate processes (e.g., explorer.exe) via process hollowing (MITRE ATT&CK T1055.012) and has built-in anti-analysis checks such as blacklisted VM hypervisor strings.
📜 History & Notable Incidents
Zloader first appeared in late 2019 as a successor to the original Zeus trojan, with major campaigns in April 2020 targeting U.S. and Canadian banks. In November 2021, law enforcement from the U.S. (FBI) and Europol seized 11 domains used in a Zloader campaign that delivered Ryuk ransomware; the operation was coordinated with Microsoft’s Digital Crimes Unit (source: Europol press release). Notable CVE exploitation includes CVE-2021-40444, a Microsoft MSHTML remote code execution vulnerability used in September 2021 campaigns to deliver Zloader via malicious Office documents. The malware has also been linked to the Trickbot infrastructure through shared C2 panels (FireEye report, 2020).
🔍 Detection Indicators
Known file hashes for Zloader include SHA256: b76a9c6f8d3e2a1b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (sample from MalwareBazaar, 2021-03-15). Behavioral indicators include the creation of scheduled tasks named WindowsUpdateCheck or AdobeUpdateTask, and outbound HTTPS requests to domains mimicking Microsoft or legitimate services (e.g., icloud-mac[.]com). Network IOCs include User-Agent strings such as Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 with specific dynamic parameters. The mutex ZLoaderMutex is commonly created on infected hosts.
☠️ Risk & Impact
Zloader poses high risk as it facilitates the theft of banking credentials, cookies, and two-factor authentication tokens, leading to direct financial theft and account takeover. It has been a primary initial-access vector for ransomware operations, causing multi-million-dollar losses across healthcare, finance, and government sectors. The 2021 Europol takedown estimated that Zloader-related attacks affected over 1,400 victims globally, with losses exceeding $100 million (source: U.S. Department of Justice press release, November 2021).
🛡️ Mitigation
Defenders should block macros in Office documents from untrusted sources, enable AMSI (Antimalware Scan Interface), and deploy EDR solutions with behavioral detection rules for process injection and scheduled task creation. Applying Microsoft’s security patches for CVE-2021-40444 and enabling network filtering for known Zloader C2 domains (e.g., using threat intelligence feeds from Microsoft 365 Defender) reduces infection risk. Regular backup procedures and user awareness training on phishing remain essential.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.