Researchers detailed how GuLoader—also tracked as CloudEyE—has operated as a long-running malware downloader that abuses legitimate cloud platforms such as Google Drive and Microsoft OneDrive to host encrypted second-stage payloads. First seen delivering Parallax RAT, the VB6-based loader was rapidly adopted by multiple threat actors and used to distribute a wide range of malware, including Agent Tesla, FormBook, NanoCore, NetWire, Remcos, Vidar, RedLine, Raccoon, and Warzone RAT. Reports tied the service to large-scale spam and archive-based delivery chains using invoice and COVID-19 lures, while one investigation linked the broader CloudEyE operation to a commercial malware protection and delivery service marketed to cybercriminals.
Technical analyses showed GuLoader evolving to make detection and reverse engineering harder, with encrypted shellcode, code randomization, process injection, anti-debugging, anti-VM timing checks, hypervisor detection, and vectored exception handling that disrupts linear debugging. Researchers described samples that decrypted embedded loader components with XOR keys, allocated memory through hidden or indirect API calls, and executed payloads through callback-based shellcode techniques after staging files and PowerShell. Multiple teams also published methods to statically unpack the loader, recover drop URLs, and decode final payloads, underscoring the continuing enterprise risk from credential theft, remote access, and follow-on compromise delivered through this inexpensive malware-as-a-service platform.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
19 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs reported recent GULOADER samples had evolved their anti-analysis logic by adding EXCEPTION_PRIV_INSTRUCTION and EXCEPTION_ILLEGAL_INSTRUCTION to the malware’s vectored exception handler workflow. The report also published YARA detection content and observables, including SHA-256 6ae7089aa6beaa09b1c3aa3ecf28a884d8ca84f780aab39902223721493b1f99 and C2 101.99.75[.]183.
A July 2023 analysis documented a multi-stage infection chain in which a Stage 2 PowerShell script downloaded a Base64 payload from 194.55.224[.]183 and extracted a Stage 3 reflective loader for GuLoader. The write-up detailed layered obfuscation, dynamic API resolution, console hiding, and the use of a 645-byte decryptor shellcode to unpack and execute encrypted GuLoader shellcode from memory.
A VinCSS analysis published in May 2023 examined a GuLoader variant received by customers in Vietnam via suspicious email attachments that downloaded NanoCore RAT from Google Drive. The report detailed anti-VM and anti-analysis checks including VMware artifact scanning with ZwQueryVirtualMemory, QEMU Guest Agent file detection, CPUID-based virtualization checks, and injection into a suspended RegAsm.exe process.
A January 2022 analysis detailed a GuLoader-attributed VBScript sample named remittence.vbs that wrote shellcode to %TEMP%\Champag6.dat and executed it through PowerShell and callback-based shellcode execution.
CERT-AgID reported that GuLoader activity reappeared in 2022, observing four new campaigns including one in April, one in mid-June, and two in mid-July.
CERT-AgID reported that GuLoader activity in Italy ceased at the end of September 2021 after six campaigns during the year, with one case showing Remcos delivery.
A technical analysis published on 2021-04-19 dissected a GuLoader sample with hash d55259bcf47af7e645ab7b003aa2cd4071cb36c6, detailing its VB wrapper, layered shellcode, anti-VM and anti-debugging checks, and breakpoint-neutralization logic. The write-up also showed GuLoader creating a suspended RegAsm.exe process, injecting a second shellcode with NtMapViewOfSection and NtWriteVirtualMemory, and using WinINet APIs such as InternetOpenUrlA to fetch additional malware.
CERT-AgID said it first observed GuLoader in Italy around the end of March 2021, where the campaigns were used mainly to deliver AgentTesla.
VMRay analyzed a spam campaign in which a malicious RTF attachment exploited CVE-2017-11882 to download GuLoader, which then retrieved AZORult from cloud-hosted infrastructure. The report also documented GuLoader anti-analysis behavior and additional enumeration of installed products and services during execution.
A technical analysis published on June 27, 2020 detailed GuLoader/CloudEyE shellcode execution, anti-analysis behavior, and injection into a suspended RegAsm.exe process using a mapped msvbvm60.dll section. The write-up also showed how the second-stage shellcode decodes a payload URL and downloads commodity malware such as Agent Tesla, FormBook, NanoCore RAT, NetWire, or Remcos.
VMRay reported that GuLoader's developers publicly announced on June 6, 2020 that they had shut down the service. The announcement came amid ongoing 2020 distribution of the malware downloader also known as CloudEyE.
K7 Labs said it first encountered the referenced GuLoader binary in March 2020 during a spam campaign that delivered FormBook. The report also noted GuLoader's use of malspam and cloud or live infrastructure to fetch later-stage payloads.
Proofpoint documented a GuLoader sample dated 2020-02-20 that used Google Drive to deliver Remcos RAT and referenced droptop1[.]com through droptop10[.]com on port 2500.
Check Point said CloudEyE customers used coronavirus-themed lures in 2020 to trick victims into opening malware delivered through GuLoader infrastructure.
Check Point reported in 2020 that CloudEyE-produced samples were effectively GuLoader, tying the malware delivery service to the older DarkEyE Protector and to securitycode.eu.
VIPRE Labs reported a spike in spam email samples delivering GuLoader from January to April 2020, using bill payment, wire transfer, and COVID-19-themed lures. The campaigns distributed GuLoader in RAR or ISO attachments and were associated with payloads such as Formbook, NetWire, Remcos, and LokiBot.
Proofpoint documented a GuLoader sample dated 2019-12-23 that used Google Drive to deliver Parallax RAT and communicated with C2 server 185.140.53.134 on port 7776.
Proofpoint said it first observed the new VB6-based downloader GuLoader in late December 2019, initially delivering Parallax RAT via cloud-hosted encrypted payloads.
Check Point reported that DarkEyE Protector, later linked to CloudEyE/GuLoader, was advertised on a hacker forum in 2014 by the user "xor," with earlier related advertisements by "sonykuccio."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
21 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcecert.pl
Open sourcelearn.microsoft.com
Open sourcelabs.vipre.com
Open sourcekienmanowar.wordpress.com
Open sourceresearch.checkpoint.com
Open sourceunit42.paloaltonetworks.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.