FakeBat, also known as EugenLoader and PaykLoader, is a Windows malware loader operated as a malware-as-a-service offering and widely used in drive-by and malvertising-driven infection chains. It emerged as one of the most prevalent loader families in the first half of 2024 and is associated with the threat actor tracked as Eugenfest, while Microsoft has also linked related activity to Storm-1113. FakeBat is primarily used to retrieve and execute follow-on payloads rather than to perform the final monetization stage itself. Common downstream payloads have included IcedID, Lumma, RedLine, SmokeLoader, SectopRAT/ArechClient2, Ursnif, and other commodity stealers and remote-access malware.
FakeBat is commonly distributed through malicious search ads, fake software download pages, SEO-poisoned or typosquatted sites, and fake browser update lures on compromised websites. Campaigns have impersonated widely used business and consumer software and have targeted opportunistically across industries, including business users searching for legitimate tools. Delivery has frequently relied on signed MSI or MSIX installers, including developer-signed MSIX packages, to improve user trust and reduce friction from Windows security prompts.
Execution chains commonly use installer components and embedded PowerShell to contact command-and-control infrastructure, fingerprint the victim environment, and download additional stages. Observed behavior includes host profiling, anti-analysis filtering, obfuscated PowerShell, staged retrieval of encrypted or compressed payloads, and use of legitimate software as a decoy during installation. FakeBat activity has also been associated with cloaking and traffic filtering on landing pages and payload infrastructure to evade researchers and automated scanning.
The malware’s core role is post-click payload delivery. In observed campaigns it has delivered infostealers, remote-access trojans, and banking malware, and it has appeared in broader criminal ecosystems that can lead to credential theft, session theft, and subsequent enterprise compromise. FakeBat has also been discussed by ransomware actors as a rentable signed-loader capability, underscoring its role as an access-enablement tool within financially motivated intrusion chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In these campaigns, GrayAlpha employed two primary types of PowerShell loaders: a self-contained custom script known as PowerNet, and a dynamic loader — a customized variant of FakeBat — referred to as MaskBat.
MSIX packages have been leveraged by threat actors such as FIN7, Zloader (Storm-0569), and FakeBat (Storm-1113) for malware delivery.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The initial PowerShell script is straightforward, downloading and executing the next-stage payload from its C2 server
By executing the MSIX file, it executes the PowerShell script “iiu.ps1” which communicates with the FakeBat C2 server
The downloaded file was a VHD container which, when mounted, revealed Installer.bat, a batch file containing simple commands intended to raise execution privileges; add scanning exclusions for Windows Defender; and download and execute a remote batch script and an executable.
In mid-December 2023, FakeBat started using a heavily obfuscated template for its initial PowerShell script.
The MaaS provides build templates to trojanise legitimate software, thus luring potential victims into executing FakeBat.
FakeBat C2 servers highly likely filter traffic based on characteristics such as the User-Agent value, the IP address, and the location. This enables the distribution of the malware to specific targets.
They perform fingerprinting via JavaScript to determine, among other things, if the user is running a virtual machine. Only after the check is successful do we see a redirect to the main landing page... there is a second fingerprinting attempt when the user clicks the download button.
From mid-August to December 2023, the FakeBat PowerShell script fingerprinted the infected host and exfiltrated the data through its C2 servers to the URL endpoint “/” using the following HTTP query parameters: av, domain, key, site, status and os.
They perform fingerprinting via JavaScript to determine, among other things, if the user is running a virtual machine. Only after the check is successful do we see a redirect to the main landing page... there is a second fingerprinting attempt when the user clicks the download button.
268 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader malware sold as Malware-as-a-Service/Loader-as-a-Service that is distributed via drive-by downloads, malvertising, fake browser updates, software impersonation, and social engineering. It delivers and executes next-stage payloads and uses PowerShell-based installers and rotating C2 infrastructure.
Named as malware associated with MSIX package abuse.
FakeBat is referenced as malware observed in recent malicious MSIX package campaigns using developer-signed MSIX packages.
Loader closely resembling BatLoader with slightly different TTPs; used in malvertising campaigns that lead to infostealer infections such as RedLine, Gozi/Ursnif, and Rhadamanthys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.