GuLoader, also known as CloudEyE, is a shellcode-based downloader targeting Microsoft Windows and active since at least 2019. It retrieves, decrypts, and executes additional malware, including Remcos, NetWire, Agent Tesla, FormBook, and LokiBot. It can obtain payloads over HTTP and through cloud-storage services such as Google Drive, separating the delivery component from the final malicious payload.
GuLoader employs extensive anti-analysis and defense-evasion techniques, including encrypted shellcode, junk instructions, convoluted jump chains, virtualization and sandbox checks, and timing-based anti-debugging. Variants use vectored exception handling to obscure control flow, redirect execution through exception contexts, and detect hardware breakpoints. It can inject shellcode into suspended donor processes and use section mapping for payload execution. NSIS-packaged variants also execute shellcode through callback-capable Windows APIs. GuLoader can establish registry-based startup persistence and delete its original executable to remove evidence.
Distribution commonly involves phishing and malicious spam using business-themed lures, malicious links, macro-enabled Word documents, and exploit-bearing Office attachments. Documented delivery chains exploit CVE-2017-0199 and CVE-2017-11882; other chains involve CVE-2023-38831 exploitation in WinRAR. Cloud-hosted ISO images and NSIS installers have also been used. GuLoader has appeared in TA558's SteganoAmor campaign, delivering FormBook, and in BoredFluff infections targeting hotel staff through fake guest enquiries before deploying Remcos. Its use spans multiple sectors rather than a single victim profile.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The article links CVE-2017-0199 to Dridex distribution in 2017, Gamaredon APT operations, and GuLoader delivery. It also describes a document exploiting this vulnerability that had only one detection after six days.
The article identifies CVE-2017-11882 among three old Microsoft Office vulnerabilities still exploited in 2023. It explicitly links this vulnerability to GuLoader in 2021 and to Agent Tesla and FormBook delivery.
CVE-2023-38831 is a vulnerability that enables malicious actors to execute arbitrary code when a user tries to access a harmless file contained within a ZIP archive.
実行ファイルが使用されるケースでは、実行ファイル自体が情報窃取型マルウェア本体である場合と、実行ファイルがGuLoader(別名:CloudEyE)と呼ばれるダウンローダである場合があります。
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This targeting profile matches a campaign documented by Agoda Engineering as “BoredFluff”, which tracked GuLoader-to-Remcos infections targeting hotel staff through fake guest enquiries.
Guloader, to be used as the loader for fetching the next piece of malware, is then downloaded.
In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
Initially identified (by researchers at CheckPoint) as Guloader, the new Visual Basic 6-based installer was tied to a publicly-marketed installation builder called CloudEyE.
In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
eSentire has observed a substantial increase in malware being delivered through tax-themed phishing emails. Cybercriminals are exploiting the urgency and importance of tax-related communications to trick individuals into opening malicious email links, leading to malware infections.
APT28 actors have exploited WinRAR vulnerability CVE-2023-38831 to drop a BAT file which opens a decoy PDF file and creates a reverse SSH shell to an attacker controlled IP address, and executes IRONJAW script using PowerShell.
“GULOADER executes shellcode through callbacks using different Windows API functions… We have observed EnumResourceTypesA and CallWindowProcW used by GULOADER.”
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
When a victim double-clicks on the PDF, the vulnerability will quietly launch a script in the folder to install malware on the device.
В данной статье мы рассмотрим более продвинутый подход к инжекту - в его основе лежит вполне легальный механизм проецирования секций памяти "Mapping"...
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
“By implementing the VEH, GULOADER flattens the control flow graph, making it harder to trace the program logic.” | “The encrypted shellcode is buried into a nested folder.”
“GULOADER comes pre-packaged inside an NSIS (Nullsoft Scriptable Install System) installer.”
В данной статье мы рассмотрим более продвинутый подход к инжекту - в его основе лежит вполне легальный механизм проецирования секций памяти "Mapping"...
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Tiếp theo sử dụng vòng lặp để quét toàn bộ vùng nhớ từ 0x00010000 tới 0x7FFFF000, gọi hàm ZwQueryVirtualMemory kiểm tra access protection của các vùng nhớ này... gặp chuỗi sẽ gọi hàm tính toán hash cho chuỗi đó và so sánh với các hash đã thiết lập trên Stack. | loader còn sử dụng thêm lệnh CPUID để kiểm tra xem chương trình có đang thực thi trong môi trường ảo hóa hay không
Tiếp theo sử dụng vòng lặp để quét toàn bộ vùng nhớ từ 0x00010000 tới 0x7FFFF000, gọi hàm ZwQueryVirtualMemory kiểm tra access protection của các vùng nhớ này... gặp chuỗi sẽ gọi hàm tính toán hash cho chuỗi đó và so sánh với các hash đã thiết lập trên Stack. | loader còn sử dụng thêm lệnh CPUID để kiểm tra xem chương trình có đang thực thi trong môi trường ảo hóa hay không
330 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
139 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned among malware deployed in separate 2024 campaigns with a comparable attack chain. No role in delivering the analyzed Remcos payload is established.
Referenced as a loader observed using section mapping via NtMapViewOfSection with SEC_IMAGE for payload loading.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
A shellcode-based, memory-resident loader/downloader attributed via C2 infrastructure in this campaign. It is described as running entirely in memory and commonly used to drop infostealers such as Lumma and Vidar and remote access tools including Remcos and AgentTesla.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.