ModiLoader, also known as DBatLoader, is a Windows malware loader used in commodity cybercrime campaigns to retrieve and execute additional payloads in memory. It has been observed delivering malware including Remcos RAT, Warzone RAT, FormBook, Agent Tesla, LokiBot, NetSupport, and other commodity families. Campaigns using ModiLoader have targeted a broad range of victims, including small and medium-sized businesses in Europe, and are generally associated with opportunistic phishing operations rather than narrowly targeted intrusions.
ModiLoader is commonly distributed through malspam and phishing lures themed around invoices, purchase orders, HR notifications, payment matters, and similar business pretexts. Observed delivery chains include malicious attachments such as ISO images, executable files disguised with document icons, password-protected archives, LNK files, HTML downloaders, and search-ms or WebDAV-based social engineering chains. Compromised email accounts and legitimate cloud-hosting services have been used to support distribution and staging.
Technically, ModiLoader is a multi-stage loader, with analyzed samples written in Delphi. It decrypts embedded resources and configuration data at runtime, reconstructs URLs or payload components, downloads encrypted follow-on stages, and executes them directly from memory. Some variants perform internet-connectivity checks before retrieving the next stage and use standard Windows networking components to fetch remote content. Later stages have been observed establishing persistence through user Run-key autostart entries and writing launcher artifacts that point to dropped executables. ModiLoader has also been associated with process injection into legitimate Windows processes as part of payload execution and evasion.
The malware’s primary role is payload delivery rather than standalone espionage or monetization. Once execution succeeds, the final malware family determines downstream activity, which may include credential theft, keylogging, remote access, and data exfiltration. ModiLoader has been linked to long-running cybercrime activity clusters such as DDGroup and has also appeared in campaigns where attackers likely used large language models to help generate phishing or downloader code. Its recurring use across multiple malware ecosystems reflects its role as a flexible loader in the commodity malware supply chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
To give an overview, here is a list of all observed tools and malware types the actor has been using in recent years: ModiLoader / DBatLoader
21 distinct techniques documented for this family, organized by ATT&CK tactic.
These messages often spoof companies sending invoices or purchase orders... The email contains an ISO image presented as a purchase order.
Opening the malicious attachment executes an HTML file with embedded JavaScript that is highly likely generated by an LLM. This script is designed to download and execute additional payloads
Opening the malicious attachment executes an HTML file with embedded JavaScript that is highly likely generated by an LLM. This script is designed to download and execute additional payloads
DBatLoader's resource section contains a GIF image as the second stage encrypted payload.
The ISO image contains a Windows executable (EXE) file for ModiLoader. The EXE file icon impersonates an Excel spreadsheet.
The encrypted byte from the resource section is added to the number 79... individual bytes are retrieved to decode the second stage DLL payload.
Therefore, the attacker copies 'easinvoker.exe' to the mock directory and uses it to load the malicious 'netutils.dll', which in turn executes the 'KDECO.bat' script.
The infected Windows host also checked its location using geoplugin.net, which is a legitimate service.
The ModiLoader EXE first generated a OneDrive URL using HTTP over TCP port 80. This redirected to an HTTPS version of the same URL over TCP port 443.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware loader observed in campaigns where use of LLM-generated HTML code was suspected.
ModiLoader is a malware loader used to deliver various payloads, including RATs and stealers, via phishing campaigns. It replaced AceCryptor in recent campaigns.
A loader listed as part of the actor’s observed malware/toolset.
A malware loader delivered via malspam ISO/EXE attachment that retrieves and executes secondary payloads. In this case, it fetched a base64-encoded payload from OneDrive and led to a Remcos RAT infection with persistence via the Windows Run registry key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.