GzipLoader is a Windows loader associated with the IcedID infection chain. It functions as an intermediate stage that retrieves, decrypts, and executes the next payload, most commonly IcedID, which is also known as BokBot. The loader is named for its use of payloads disguised as GZIP-compressed content and has also been referred to as the IcedID downloader. In observed campaigns, GzipLoader serves as the first-stage DLL or executable that fingerprints the victim host, communicates with command-and-control infrastructure, and conditionally downloads additional encrypted components for execution.
GzipLoader has been delivered through malicious Office documents that prompt users to enable macros, including Excel and Word lures used in phishing campaigns. These documents typically download and launch an executable or DLL that starts the loader stage. Related delivery chains have also used fake software download pages, including counterfeit application installers, to distribute GzipLoader. Once running, the malware can collect host profiling data such as operating system details and other machine characteristics before contacting its controllers, likely to filter victims and evade sandbox or analyst environments.
Technical reporting has documented anti-analysis evolution in GzipLoader, including dynamic Windows API resolution and XOR-obfuscated stacked strings, as well as earlier variants that implemented SSL pinning behavior. The loader has been observed extracting or downloading a second-stage DLL and encrypted data blob, then invoking execution through native Windows utilities. Its role is primarily to establish the next stage of compromise rather than to perform the full range of banking-trojan or hands-on-keyboard activity itself.
GzipLoader is closely tied to financially motivated and intrusion-enabling operations built around IcedID. Campaigns using this loader have targeted enterprises and government entities, including Ukrainian organizations and citizens in phishing operations attributed by defenders to clusters such as UAC-0041 and UAC-0098. Because IcedID infections frequently progress to delivery of frameworks such as Cobalt Strike and, in some cases, ransomware or destructive payloads, GzipLoader is best understood as a key access-enablement component in a broader multi-stage intrusion ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Завантажений EXE-файл забезпечить дешифрування та запуск на комп'ютері шкідливої програми GzipLoader, яка, в свою чергу, здійснить завантаження, дешифрування та запуск шкідливої програми IcedID.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
у разі відкриття документу та активації макросу, останній забезпечить завантаження і запуск виконуваного файлу
The second functionality that has been added to the new loader is string encryption: Strings are hidden using a technique commonly known as stacked strings, which is combined with simple XOR encryption.
This data is not downloaded as plaintext but hidden via steganography techniques. At the time of the analysis the data was hidden behind a fake GZIP header, and previously we also observed fake JPG images.
Strings are hidden using a technique commonly known as stacked strings, which is combined with simple XOR encryption.
The loader will locate the encrypted payload, stored in the resource section of the binary. It does this through the technique API hashing.
Despite the “.jpg” extension, this file is actually a DLL, and gets executed via rundll32.exe calling the “PluginInit” exported function as an entry point.
Завантажений EXE-файл забезпечить дешифрування та запуск на комп'ютері шкідливої програми GzipLoader, яка, в свою чергу, здійснить завантаження, дешифрування та запуск шкідливої програми IcedID.
Ultimately, the sample will download the 1 st stage DLL and execute it using rundll32... The DLL is executed using the rundll32 executable.
233 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader/downloader used at the start of the infection chain to retrieve and deliver the IcedID DLL and license.dat via a fake gzip file.
GzipLoader is referenced as the loader stage used to deliver the IcedID payload in this infection chain, masquerading as part of a fake Microsoft Teams download and fake gzip content.
Loader malware that decrypts and launches a secondary payload, specifically IcedID, after execution from the malicious XLS macro chain.
A loader used in the phishing chain to fetch, decrypt, and execute the final IcedID payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.