PowerLoader is a name associated with Windows malware loaders and downloaders. Historical PowerLoader 2.0 is notable for injecting code into Windows Explorer using Extra Window Memory Injection. It places shellcode in existing shared memory, manipulates Explorer's window data, and redirects execution through legitimate executable code and a return-oriented programming chain. This approach avoids remote memory allocation and new-thread creation during injection and enables payload execution despite Data Execution Prevention. Similar injection techniques have appeared in Carberp, Redyms, and Gapz.
The PowerLoader name was also used for a C++ downloader deployed by Fluffy Wolf in phishing campaigns against Russian organizations between March and May 2026. Marketed through malware-as-a-service offerings, this downloader operates largely filelessly, launches hidden PowerShell instances, retrieves scripts from command-and-control infrastructure, and downloads and executes PureCrypter to deliver subsequent payloads. Campaign payloads included PureLogs, PureRAT, and Pay2Key ransomware. Distribution used business-themed phishing emails impersonating partners or contractors, with malicious archives attached directly or supplied through GitHub repository links. Targeted sectors included construction, consulting, manufacturing, engineering, retail, and e-commerce.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PowerLoader is an undocumented C++ downloader that executes almost entirely filelessly to bypass standard endpoint defenses like Windows Defender.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Security researchers have uncovered a series of highly sophisticated Fluffy Wolf phishing attacks targeting Russian organizations across various critical sectors.
Using highly deceptive tactics, the attackers send emails masquerading as legitimate corporate communications regarding outstanding debts, reconciliation statements, or legal claims. To bypass modern email security gateways, the attackers heavily rely on malicious RAR attachments...
EXTRA WINDOW MEMORY INJECTION (EWMI) VIA SETWINDOWLONG EWMI relies on injecting into Explorer tray window’s extra window memory... | Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process.
EXTRA WINDOW MEMORY INJECTION (EWMI) VIA SETWINDOWLONG EWMI relies on injecting into Explorer tray window’s extra window memory... | Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Malware-as-a-Service C++ downloader used by Fluffy Wolf that operates largely filelessly, spawns hidden PowerShell to fetch scripts from C2, and deploys final payloads including Pay2Key, PureLogs, and PureRAT.
Новый загрузчик на C++, запускающий PowerShell в скрытом режиме и получающий скрипты с управляющего сервера; затем скачивает и запускает PureCrypter.
Referenced alongside Gapz as an example of an existing code-injection technique, identified as EWMI. No additional malware behavior, targeting, or campaign details are provided.
Malware shown using extra window memory injection into the Explorer shell tray window via SetWindowLong and SendNotifyMessage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.