Names | CoreLoader | |
Category | Malware | |
Type | Loader | |
Description | (Kaspersky) CoreLoader, the last malware we found associated to this set of activity, is a simple shellcode loader which performs anti-analysis and loads additional code from a file named WsmRes.xsl. Again, this specific file eluded our attempts to catch it but we suspect it to be, one way or another, related to FoundCore (described in the previous section). | |
Information | <https://securelist.com/the-leap-of-a-cycldek-related-threat-actor/101243/> |
Last change to this tool card: 15 May 2021
Download this tool card in JSON format
Previous: Corentry
Next: CORESHELL
Changed | Name | Country | Observed | ||
APT groups | |||||
Goblin Panda, Cycldek, Conimes | 2013-Jun 2020 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |