SYMBOLCOMMON_NAMEaka. SYNONYMS
ps1.eugenloader (Back to overview)

EugenLoader

aka: FakeBat, NUMOZYLOD, PaykLoader

Actor(s): APOTHECARY SPIDER, Storm-1113


A loader written in Powershell, usually delivered packaged in MSI/MSIX files.

References
2025-06-13 ⋅ Recorded Future ⋅ Insikt Group
GrayAlpha Uses Diverse Infection Vectors to Deploy PowerNet Loader and NetSupport RAT
EugenLoader POWERTRASH NetSupportManager RAT
2024-11-21 ⋅ Intrinsec ⋅ CTI Intrinsec, Intrinsec
PROSPERO & Proton66: Uncovering the links between bulletproof networks
Coper SpyNote FAKEUPDATES GootLoader EugenLoader
2024-11-20 ⋅ Intrinsec ⋅ Equipe CTI
PROSPERO & Proton66: Tracing Uncovering the links between bulletproof networks
Coper SpyNote FAKEUPDATES GootLoader EugenLoader IcedID Matanbuchus Nokoyawa Ransomware Pikabot
2024-08-13 ⋅ Google ⋅ Google
Finding Malware: Unveiling NUMOZYLOD with Google Security Operations
EugenLoader UNC4536
2024-07-02 ⋅ Sekoia ⋅ Quentin Bourgue
Exposing FakeBat loader: distribution methods and adversary infrastructure
BlackCat Royal Ransom EugenLoader Carbanak Cobalt Strike DICELOADER Gozi IcedID Lumma Stealer NetSupportManager RAT Pikabot RedLine Stealer SectopRAT Sliver SmokeLoader Vidar
2023-12-30 ⋅ Rewterz Information Security ⋅ Rewterz Information Security
Rewterz Threat Alert – Widely Abused MSIX App Installer Disabled by Microsoft – Active IOCs
EugenLoader POWERTRASH BATLOADER DarkGate FlawedGrace NetSupportManager RAT SectopRAT Storm-0506
2023-12-12 ⋅ eSentire ⋅ Rob Pittman
Unraveling BatLoader and FakeBat
EugenLoader
2023-02-28 ⋅ Intel 471 ⋅ Intel 471
Malvertising Surges to Distribute Malware
EugenLoader BATLOADER IcedID

There is no Yara-Signature yet.