Researchers linked Batloader activity to the Water Minyades / DEV-0569 / SteelClover ecosystem, which used malvertising, SEO poisoning, and fake software download pages to lure victims into installing trojanized packages. The campaigns abused legitimate installer frameworks such as Advanced Installer and WiX, then shifted to obfuscated JavaScript and PyArmor-protected Python loaders that fingerprinted hosts, contacted command-and-control infrastructure, escalated privileges, and attempted to disable security tools. Operators also used cloned software sites and malicious Google ads to distribute MSI files that launched PowerShell, added Microsoft Defender exclusions, and retrieved encrypted follow-on payloads.
The infections were used to selectively deploy a broad set of malware, including Qakbot, Ursnif, Vidar, ZLoader, RedLine Stealer, Raccoon Stealer, Cobalt Strike, and remote-management tools such as Atera and Syncro. Trend Micro reported that Batloader infections observed from September 2022 onward were associated with Royal ransomware, while NTT documented a surge of related infections at Japanese companies in early 2023 through the FakeGPG and BatApp campaigns. The activity was concentrated heavily in the United States but also affected Canada, Germany, Japan, and the United Kingdom, underscoring Batloader's role as a flexible initial-access platform for both credential theft and ransomware intrusion chains.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
Seqrite published an analysis of a BATLOADER 2.x infection chain in which a cabinet archive posing as cracked software led to a multi-stage batch and PowerShell loader that dropped AsyncRat. The report also disclosed technical details including AMSI and ETW bypasses, persistence methods, C2 fallback to jzx100.myddns.me, and file-hash IOCs.
In June 2023, Trend Micro observed Water Minyades upgrading Batloader campaigns by using Pyarmor Pro to obfuscate core malicious Python scripts. The report detailed an oversized MSI-based infection chain that installed WinRAR, unpacked Pyarmor-protected payloads, fingerprinted victims, and communicated with countingstatistic[.]com before delivering second-stage malware.
In mid-February 2023, eSentire said a manufacturing customer clicked a malicious Google Search ad for Adobe Reader, downloaded a fake Adobe MSI from a typo-squatted domain, and triggered BatLoader activity that attempted to deploy an Ursnif isfb_v2.14+ payload. The report disclosed that the BatLoader sample used embedded batch and PyArmor-protected Python scripts, disabled parts of Microsoft Defender, decrypted a payload from shvarcnegerhistory[.]com, and executed it via WorkFolders.exe before eSentire blocked the activity.
As of early February 2023, NTT Security Japan was observing the BatApp and FakeGPG campaigns associated with SteelClover. The report said SteelClover overlaps with DEV-0569 and Water Minyades and uses Batloader-related tradecraft.
NTT Security Japan reported a sharp increase in incidents at multiple Japanese companies beginning in early January 2023, driven by malware downloads initiated through malicious Google ads. The activity was attributed to the group it tracks as SteelClover.
In December 2022, Water Minyades used JavaScript instead of MSI files as the first-stage Batloader payload and later obfuscated the JavaScript downloader. This represented a delivery-chain change from earlier MSI-heavy campaigns.
Trend Micro said Batloader attack volume peaked from November through the first week of December 2022. The period fell within the broader Q4 2022 campaigns the company analyzed.
In October 2022, Water Minyades abused Google Ads and the Keitaro Traffic Direction System to redirect victims to Batloader downloads. This marked a notable expansion of the group's malvertising infrastructure.
Trend Micro observed Batloader MSI packages abusing Advanced Installer software between September and December 2022. These MSI-based campaigns used malicious custom actions as part of the infection chain.
Trend Micro observed that from September 2022, initial Batloader infections were leading to Cobalt Strike deployments and Royal ransomware infections. The report characterized Batloader as a key enabler for Royal ransomware.
eSentire reported BatLoader infections in September 2022 across consumer services, retail, telecommunications, and non-profit organizations, and a second campaign in October-November 2022 affecting insurance, consulting, healthcare, and printing. The analysis disclosed distinct signed MSI lures, campaign-specific C2 domains, host-profiling logic, Defender tampering, and payload delivery including Ursnif/ISFB, Vidar, Cobalt Strike, and Syncro RMM.
VMware Carbon Black MDR reported observing BatLoader campaigns as early as July 2022, describing them as prevalent across customer environments, especially in business and financial services. The campaigns used SEO poisoning and trojanized MSI installers posing as software like Zoom, TeamViewer, and AnyDesk to deliver follow-on payloads including Ursnif/Gozi, Arkei/Vidar, and sometimes a Cobalt Strike stager.
In February 2022, Water Minyades distributed Batloader via SEO poisoning. Trend Micro also said the actor used PE polyglotting to execute signed DLL files with appended malicious scripts.
In October 2020, Water Minyades moved from exploit kits to social-engineering campaigns using malicious ads on porn websites. Those campaigns delivered fake Java MSI files that deployed ZLoader.
In the second half of 2020, Water Minyades relied heavily on SmokeLoader and exploit kits including Rig and Fallout. This reflects an earlier delivery phase before the group's later Batloader-focused operations.
Trend Micro reported that the intrusion set it tracks as Water Minyades had activity dating back to early 2020. This establishes the earliest known timeframe for the actor later associated with Batloader.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
seqrite.com
Open sourcetrendmicro.com
Open sourceesentire.com
Open sourceesentire.com
Open sourceinsight-jp.nttsecurity.com
Open sourcetrendmicro.com
Open sourceblogs.vmware.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.