SYMBOLCOMMON_NAMEaka. SYNONYMS
js.mints_loader (Back to overview)

MintsLoader


According to Orange Cyberdefense, MintsLoader is a little-known, multi-stage malware loader that has been used since at least February 2023. It has been observed in widespread distribution campaigns between July and October 2024. The name comes from a very characteristic use of an URL parameter “1.php?s=mintsXX" (with XX being numbers).

MintsLoader primarily delivers malicious RAT or infostealing payloads such as AsyncRAT and Vidar through phishing emails, targeting organizations in Europe (Spain, Italy, Poland, etc.). Written in JavaScript and PowerShell, MintsLoader operates through a multi-step infection process involving several URLs and domains, most of which use a domain generation algorithm (DGA) with .top TLD.

References
2025-12-18 ⋅ BlackPoint ⋅ Nevan Beal, Sam Decker
New MintsLoader Variant Using Hashtable Obfuscation
MintsLoader
2025-08-06 ⋅ Silent Push ⋅ Silent Push
Unmasking SocGholish: Silent Push Untangles the Malware Web Behind the “Pioneer of Fake Updates” and Its Operator, TA569
FAKEUPDATES MintsLoader Parrot TDS Parrot TDS WebShell Raspberry Robin
2025-04-29 ⋅ Recorded Future ⋅ Insikt Group
Uncovering MintsLoader With Recorded Future Malware Intelligence Hunting
FAKEUPDATES MintsLoader GhostWeaver Stealc TAG-124
2025-03-07 ⋅ ⋅ Youtube (greenplan) ⋅ greenplan
[BINARY REFINERY] (MintsLoader) - Writing a Unit to deobfuscated JavaScript payload
MintsLoader
2025-02-22 ⋅ ⋅ Youtube (greenplan) ⋅ greenplan
[BINARY REFINERY] (MintsLoader) - Deobfuscation of a simple XOR to get the URL
MintsLoader
2025-01-30 ⋅ Recorded Future ⋅ Insikt Group
TAG-124’s Multi-Layered TDS Infrastructure and Extensive User Base
Rhysida KongTuke MintsLoader Broomstick Remcos Rhysida WarmCookie
2025-01-16 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
MintsLoader: StealC and BOINC Delivery
MintsLoader Stealc
2024-12-12 ⋅ Spamhaus ⋅ Spamhaus Team
PEC “invoice scam” - Stealing time, money, and trust from businesses
MintsLoader
2024-10-31 ⋅ nikhilh-20 ⋅ Nikhil Hegde
Deobfuscating JavaScript Malware Using Abstract Syntax Trees
MintsLoader
2024-10-24 ⋅ Orange Cyberdefense ⋅ Alexis Bonnefoi, Marine PICHON, Vincent HINDERER
MintsLoader
MintsLoader
2024-10-24 ⋅ Orange Cyberdefense ⋅ Alexis Bonnefoi, Marine PICHON, Vincent HINDERER
Twitter Thread about MintsLoader
MintsLoader
2024-07-17 ⋅ Huntress Labs ⋅ Alden Schmidt, Greg Linares, Matt Anderson
Fake Browser Updates Lead to BOINC Volunteer Computing Software
FAKEUPDATES MintsLoader AsyncRAT
2024-01-05 ⋅ AlienLabs ⋅ Fernando Martinez
AsyncRAT loader: Obfuscation, DGAs, decoys and Govno
MintsLoader AsyncRAT

There is no Yara-Signature yet.