BaoLoader is a long-running Windows malware operation centered on trojanized utility and productivity applications, especially fake or bundled PDF-related software and similar consumer tools. It is best characterized as a loader and backdoor platform rather than merely a potentially unwanted application. Campaigns associated with BaoLoader have used extensive abuse of legitimate code-signing certificates, including certificates obtained through actor-controlled shell companies, to make installers and payloads appear trustworthy and reduce user and security-product suspicion.
BaoLoader has been linked to applications and installers marketed as PDF editors, manual viewers, and other broad-audience utilities, and has also appeared in bundled or advertising-driven distribution chains. Delivery has been observed through malvertising, drive-by style download flows, and software lures that users may install unintentionally while seeking legitimate tools. Some related campaigns used broad consumer-themed lures rather than narrowly targeted enterprise pretexts.
On execution, BaoLoader commonly abuses legitimate Windows components and bundled runtime software to stage malicious activity while blending into normal system behavior. A notable pattern is the use of node.exe to execute malicious JavaScript for reconnaissance, in-memory command execution, and persistent backdoor access. Operators have also used scheduled tasks for persistence, heavy command obfuscation, multi-stage fileless execution with PowerShell and other built-in utilities, and covert command-and-control routing through legitimate cloud services to hinder detection and analysis. Associated installers and follow-on components have also shown browser-manipulation and hijacking behavior in some campaigns.
The malware family has been active since at least 2018 and has been associated with repeated certificate revocation-and-replacement cycles across numerous signer identities and certificate authorities. Reporting distinguishes BaoLoader from ChromeLoader and TamperedChef despite some thematic overlap in fake-application campaigns and browser-hijacking activity. BaoLoader has been prominent in enterprise incident response observations, where it has served as an initial-access and post-exploitation foothold capable of reconnaissance, in-memory execution, persistence, and backdoor operations on victim systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
In fact, the malware shares many similarities, such as ... Use scheduled tasks for persistence mechanism
These files... exhibit behavior that most SOC analysts will recognize as known and/or expected Web Companion behavior, executing the following PowerShell: “C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe” -noninteractive -ExecutionPolicy bypass -c ... [WebCompanion.StartUp]::Start()
The team of malicious actors used the “Drake Media Inc” certificate to sign the file “EmuWCOfferSetup-1.0.0.110.msi” ... later distributed disguised as games... with the BaoLoader malware specifically, the lures are normally productivity apps (PDF Editors and popular collaboration tools).
The application is primarily treated as a PUP, but also appears to use the same covert network communication mechanisms as AppSuite.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A trojanized-application malware family mentioned as a distinct family from TamperedChef and as background context for the broader trend of fake utility apps.
Mentioned only as another malware example that used code-signing certificates in a separate campaign.
Named loader referenced in relation to AppSuite certificate history; no technical detail is provided in the content beyond the name and association.
Signed malware/loader that uses legitimately obtained code-signing certificates to appear trustworthy, executes malicious JavaScript via node.exe for recon and in-memory command execution, provides backdoor access, and hides C2 traffic via legitimate cloud services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.