TinyLoader is a Windows malware downloader associated with the Neverquest/Vawtrak crimeware ecosystem and used in multi-stage intrusion chains to retrieve and execute additional payloads. It has been observed as a secondary component delivered by Vawtrak infections and later used to install other malware families including AbaddonPOS, Fleercivet/Bagsu, ReactorBot/Rovnix, and Diamotrix. Later reporting also noted TinyLoader being downloaded and executed by Bokbot/IcedID, indicating continued utility across related financially motivated malware operations.
TinyLoader uses a custom command-and-control protocol to fetch executable payloads. It includes environment-awareness logic such as checking whether it is running under x86 or x64 conditions, and it supports persistence on infected Windows systems through autorun mechanisms, including Run-key persistence and execution via regsvr32 when deployed as a DLL. Code-level similarities between TinyLoader and AbaddonPOS, particularly in anti-analysis and shellcode-encoding routines, suggest close development or operational linkage.
Operationally, TinyLoader has been tied to campaigns centered on banking malware and point-of-sale compromise. In documented infection chains, Vawtrak delivered TinyLoader, which then staged further downloader components or directly enabled deployment of payment-card malware such as AbaddonPOS. It has also appeared in broader bundled malware ecosystems where loaders and stealers are combined to deliver follow-on payloads. The malware is best characterized as a modular downloader used to extend access and deliver financially motivated malware to Windows victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
AbaddonPOS implements several basic anti-analysis and obfuscation techniques... This shellcode is encoded using a 4-byte XOR key; however the key is not hardcoded.
Through an email, a YouTube video, a link, or a file masquerading as something legitimate, victims can unknowingly receive an entire malware bundle.
the purpose of which is to manually craft a HTTP request that is then used to download an AbaddonPOS payload
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader malware used to deploy multiple complementary malware families, including execution chains leading to Diamotrix.
Loader observed uploaded alongside a TinyPOS sample and communicating with known infrastructure associated with the threat actor discussed in the content.
Loader malware associated with both Neverquest and Bokbot; used to download additional payloads, including AbaddonPOS in the Neverquest case.
Loader mentioned as an additional payload Vawtrak may download; previously observed installing AbaddonPOS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.