Industrial companies in Europe targeted with GuLoader

Teilen:

A recent spear-phishing campaign targeting industrial and engineering companies in Europe was aimed at saddling victims with the popular GuLoader downloader and, ultimately, a remote access trojan that would permit attackers to steal information from and access compromised computers whenever they wish.

The emails are sent from various email addresses including from fake companies and compromised accounts. The emails typically hijack an existing email thread or request information about an order,” Tara Gould, Threat Research Lead at Cado Security, has warned.

The malware

The goal of the email is to make the recipient download the attachment – an .iso.7z.gzip oder .rar archive file – and unpack it. In it is a batch file that contains an obfuscated PowerShell script.

Running the file starts a process of downloading another file containing a second PowerShell script which includes functionality to allocate memory via VirtualAlloc (a native Windows API function) and to execute shellcode.

“The second shellcode is injected into the legitimate ‘msiexec.exe’ process and appears to be reaching out to a domain to retrieve an additional payload, however at the time of analysis this request returns a 404. Based on previous research of GuLoader, the final payload is usually a RAT including Remcos, NetWire, and AgentTesla,” Gould shared.

The second script also creates a registry key for persistence.

Evasion and obfuscation is critical for GuLoader

“Guloader makes use of process injection to evade detection. This allows malicious code to be run through a legitimate process, meaning security products may not detect the malware, or victims may not be alerted since the process will look like a normal Windows process,” Gould told Help Net Security.

“The obfuscation methods are custom and deployed to bypass security products that may detect the files if they were not obfuscated and make analyzing the files more difficult.”

The evasiveness of the loader means that the threat actors deploying it can use a variety of final payloads without having to customize each one for evading detection.

“The anti-analysis techniques employed, including use of junk code and encrypted shellcode make analysis more difficult, which in turn makes creating detections more challenging. Additionally, as it is designed to disrupt analysis, more time is spent for security staff to determine what is occurring,” Gould concluded.

The targets

Cado Security has provided indicators of compromise and Yara rules to help organizations search for evidence of compromise.

The company says that the spear-phishing campaign targeted employees at electronic manufacturing, engineering and industrial companies in European countries: Romania, Poland, Germany and Kazakhstan.

Zeljka Zorz

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:05 pm, Juni 29, 2025
Wetter-Symbol 28°C
L: 26° | H: 29°
klarer Himmel
Luftfeuchtigkeit: 51 %
Druck: 1024 mb
Wind: 5 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 5%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:46 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
26° | 29°°C 0 mm 0% 4 mph 54 % 1024 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
20° | 35°°C 0 mm 0% 8 mph 71 % 1021 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
22° | 33°°C 0 mm 0% 12 mph 70 % 1017 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
16° | 22°°C 1 mm 100% 11 mph 94 % 1017 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 20°°C 1 mm 100% 12 mph 95 % 1026 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
28° | 29°°C 0 mm 0% 3 mph 47 % 1024 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 4 mph 39 % 1022 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 3 mph 54 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 3 mph 65 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 4 mph 71 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 4 mph 62 % 1020 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
28° | 28°°C 0 mm 0% 5 mph 43 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
33° | 33°°C 0 mm 0% 6 mph 29 % 1017 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,305.15
0.75%
Ethereum(ETH)
€2,094.62
1.13%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.88
0.36%
Solana(SOL)
€129.48
3.52%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.140395
1.62%
Shiba Inu(SHIB)
€0.000010
1.94%
Pepe(PEPE)
€0.000009
2.87%
Nach oben scrollen