DMLOADER is a loader malware strain used by the Earth Kurma APT as part of its persistence and payload delivery chain in intrusions targeting government and telecommunications organizations in Southeast Asia, including victims in the Philippines, Vietnam, Thailand, and Malaysia. Reporting places its use between 2022 and 2024, with Earth Kurma activity assessed to date back to at least 2020. DMLOADER is one of several loaders used alongside DUNLOADER and TESDAT. Its role is to maintain footholds and load next-stage payloads directly into memory for execution. More specifically, DMLOADER has been observed loading an embedded payload and decoding it as an in-memory PE buffer rather than loading an additional payload file from disk. Earth Kurma used these loaders to deliver Cobalt Strike beacons, and the broader attack chain also involved deployment of rootkits such as KRNRAT and MORIYA and data-exfiltration tooling. The campaign is associated with cyberespionage and data theft against primarily government and telecom targets. No initial infection vector or DMLOADER-specific indicators of compromise are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Persistence on the hosts is accomplished by three different loader strains referred to as DUNLOADER, TESDAT, and DMLOADER, which are capable of loading next-stage payloads into memory and executing them.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom loader used for persistence and deployment of additional payloads.
Loader used to deliver secondary payloads, explicitly including Cobalt Strike beacons; part of the persistence and execution chain.
Loader used for persistence and in-memory execution of next-stage payloads (e.g., Cobalt Strike beacons, rootkits, and exfiltration malware).
DMLOADER is a loader that decodes and loads embedded payloads directly into memory, used by Earth Kurma for persistence and further malware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.