SYMBOLCOMMON_NAMEaka. SYNONYMS
win.dracu_loader (Back to overview)

DracuLoader

Actor(s): Earth Estries


Cyber Defense Institute stated that this shellcode PE loader was observed staging win.hemigate.

References
2024-01-25JSAC 2024Hara Hiroaki, Kawakami Ryonosuke, Shota Nakajima
The Secret Life of RATs: connecting the dots by dissecting multiple backdoors
DracuLoader GroundPeony HemiGate PlugX

There is no Yara-Signature yet.