TransferLoader is a Windows malware family used as a stealthy follow-on payload in intrusion chains associated with the UNK_GreenSec cluster and linked through overlapping tradecraft and infrastructure to activity around TA829/RomCom. First identified in early 2025, it combines downloader, backdoor, and backdoor-loader functionality, enabling operators to deepen access on compromised hosts, retrieve and execute additional payloads, and prepare systems for later-stage criminal operations including ransomware deployment. It has been observed in campaigns targeting North America and has also been discussed in the broader context of operations affecting Ukrainian, Polish, and some Russian entities.
TransferLoader has been delivered through phishing campaigns, especially job-application-themed lures, and has also appeared after earlier compromise by other malware such as RomCom-related tooling. Campaigns have used spoofed cloud-storage themes, redirector infrastructure, and signed executables masquerading as benign documents or readers. The malware employs multiple anti-analysis and defense-evasion measures, including encrypted or obfuscated strings, custom decoding and cryptographic routines, dynamic API resolution, filename checks before execution, and decoy document display to mask malicious activity.
Operationally, TransferLoader serves as an intermediate access and payload-delivery component. It has been observed dropping or launching additional malware and offensive tooling, including Morpheus ransomware, Metasploit-related payloads, and other malware families such as MeltingClaw and DustyHammock. Its role in these chains makes it a flexible post-compromise loader and backdoor that supports persistence of access, execution of follow-on code, and transition from initial intrusion to monetization or broader malicious objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TransferLoader combines a downloader, a backdoor, and a backdoor loader to enable threat actors to make changes to compromised systems and insert ransomware or other malware. It was first discovered when it was used to load Morpheus ransomware into an American law firm’s system.
TransferLoader combines a downloader, a backdoor, and a backdoor loader to enable threat actors to make changes to compromised systems and insert ransomware or other malware. It was first discovered when it was used to load Morpheus ransomware into an American law firm’s system.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
We discovered that 27 domains—24 for TransferLoader and three for RomCom—were deemed likely to turn malicious upon registration. | We began our analysis by looking for domains that not only looked similar to those tagged as IoCs but were also registered in bulk along with the IoCs... We discovered that four domains tagged as IoCs, all tied to TransferLoader, were part of five typosquatting groups.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware loader associated with a cluster tracked as UNK_GreenSec; used to deliver additional payloads.
A named malware family discussed as a primary subject; the content analyzes TransferLoader-linked domains, typosquatting clusters, and related infrastructure artifacts used in attacks.
Stealthy malware loader that combines downloader, backdoor, and loader functionality to modify compromised systems and deploy additional payloads including ransomware and other malware. The content notes decoy PDF opening for masking execution and use in phishing and post-RAT compromise chains.
Malware used as a payload in phishing-driven campaigns attributed to UNK_GreenSec; delivered via redirect links/PDF lures and supported by infrastructure using REM Proxy services via compromised MikroTik routers and sandbox-evasion filtering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.