Buer Loader emerged as a commercially sold malware downloader that operators used to compromise Windows systems and deliver follow-on payloads including TrickBot, Cobalt Strike, KPOT, Amadey, Smoke Loader, and activity linked to Ryuk ransomware. Researchers reported that it was marketed on underground forums as an off-the-shelf service with setup support and updates, then spread through multiple infection chains including macro-enabled Word documents, malvertising, exploit kits, Ostap-based email campaigns, and later spam waves themed around DHL shipping and COVID-19 lures. Trend Micro also documented signed XLL files used as a delivery mechanism, including samples signed with a Sectigo-issued certificate that was later revoked.
The malware later evolved from a C-based loader into a Rust-based variant often called RustyBuer, while keeping compatibility with existing command-and-control infrastructure and operator panels. Analyses described layered anti-analysis and evasion features including geofencing to avoid CIS countries, debugger and sandbox checks, virtualization detection, long or CPU-intensive delays, decoy Windows API calls, API hashing, encrypted HTTPS tasking, and persistence through RunOnce or LNK methods. Researchers were still able to extract second-stage payloads from 2021 samples by recovering embedded keys and decrypting and decompressing protected data, showing that Buer remained under active development even as its core role as a first-stage malware delivery platform stayed the same.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
TEHTRIS analyzed Rust-based Buer Loader samples observed between July and August 2021. The samples used a Rust stage1 loader to decrypt and load a Rust stage2 payload in memory.
In July 2021, Trend Micro observed Buer Loader being delivered through a signed XLL file. The XLLs were signed with Sectigo OV code-signing certificates, including one tied to khorum[.]ru that was later revoked by Sectigo.
In May 2021, Walmart Global Tech published analysis of updated Buer Loader capabilities, including a DomainInfo module that profiles infected hosts and joined networks and posts the results to Buer command-and-control infrastructure. The report also described Buer's ability to load shellcode tasks directly, enabling delivery of Cobalt Strike without a separate stager, and noted panel features supporting spam operations.
An April 2021 spam campaign masquerading as DHL shipping notices distributed a new Rust-written variant of Buer Loader. The campaign used malicious Word or Excel attachments, including lures that combined DHL branding with COVID-19 themes.
Trend Micro reported that a newer Buer Loader variant rewritten in Rust, known as RustyBuer, was observed in the second quarter of 2021.
Trend Micro reported that Buer delivery moved away from Google Docs and began using Constant Contact in October 2020.
By September 2020, Trend Micro reported that Buer Loader had gained popularity as an alternative to Emotet for distributing Ryuk-associated payloads.
On October 21, 2019, Proofpoint observed malicious emails with subjects such as "Penalty Notice # PKJWVBP" carrying macro-enabled Word documents that executed Ostap. Ostap downloaded Buer, which then loaded a The Trick variant known as ono22.
On October 10, 2019, Proofpoint observed a malvertising campaign in Australia redirecting victims to the Fallout Exploit Kit, which dropped Buer. Buer then delivered KPOT stealer, Amadey, and Smoke Loader as second-stage payloads.
Proofpoint observed additional campaigns in September and October 2019 from the same actor delivering either Dreambot Ursnif or the new Buer loader.
On August 28, 2019, Proofpoint observed a malicious reply-chain email campaign using macro-enabled Word documents to download an undocumented loader later linked to Buer. The downloaded payloads were named verinstere222.xls or verinstere33.exe.
Proofpoint linked Buer activity to an underground forum advertisement posted on August 16, 2019. The loader was marketed for $400 with setup assistance, free updates and bug fixes, and extra fees for rebuilding to new addresses.
Proofpoint reported that it had tracked Buer since late August 2019 as a new modular first-stage downloader emerging in criminal delivery chains.
Malpedia published an autogenerated YARA rule named win_buer_auto for detecting the win.buer malware family. The rule metadata attributes authorship to Felix Bilstein, notes yara-signator as the generation tool, and sets matching conditions including a file size limit and sequence-based detection logic.
TEHTRIS published analysis of a Rust-based Buer Loader strain and described methods to extract its embedded stage2 payload from samples observed in mid-2021.
Trend Micro published a review of 2021 Buer Loader campaigns, highlighting Rust-based spam operations, COVID-19-themed lures, and signed XLL delivery techniques.
Proofpoint documented a new Buer Loader variant written in Rust in 2021, marking a significant rewrite from the earlier C-based implementation while preserving core loader behavior.
Proofpoint publicly analyzed Buer in December 2019, describing it as a modular loader sold on underground forums and used across email and exploit-kit delivery chains.
8 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcetehtris.com
Open sourcetrendmicro.com
Open sourcemedium.com
Open sourceproofpoint.com
Open sourceproofpoint.com
Open sourcetrendmicro.com
Open sourcecert.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.