Researchers reported that DBatLoader—also tracked as ModiLoader and NatsoLoader—has been used in multiple malware delivery campaigns that start with social engineering and end with remote-access trojans such as Remcos RAT and Warzone RAT. In one observed intrusion, a purchase-order themed malspam message carried an ISO attachment containing a Windows executable disguised with an Excel icon; after execution, the loader retrieved a 4.3 MB base64 text file from OneDrive, decoded additional components on the host, and led to TLSv1.3 command-and-control traffic with 146.70.158[.]105 over TCP 9138, consistent with Remcos activity. Another sample abused Discord attachment URLs to fetch a second Delphi-based stage and ultimately deploy Warzone RAT, which communicated over TCP 1990.
Technical analyses describe DBatLoader as a Delphi-based loader that uses multilayer obfuscation, image steganography, and in-memory decoding before dropping batch scripts, DLLs, and executables into C:\Users\Public\Libraries. It establishes persistence through HKCU\Software\Microsoft\Windows\CurrentVersion\Run, malicious shortcuts, and copied binaries, while some variants also abuse a Mock Trusted Directories UAC bypass and a relative-path DLL hijack involving easinvoker.exe and netutils.dll to gain elevated execution without a UAC prompt. Researchers said the malware commonly pulls later-stage payloads from public cloud services including OneDrive, Google Drive, and Discord, and has been seen distributing Formbook, Netwire RAT, Remcos RAT, and Warzone RAT against business users, including targets in Europe.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
A phishing campaign used an HTML attachment named PO-2200934-KINQTE.html that unpacked a RAR archive containing a DBatLoader executable, which then downloaded an encrypted next-stage payload from OneDrive. The decrypted payload was identified as WarZone RAT, and the analysis published hashes for the lure and payloads plus the C2 endpoint halal[.]home-webserver[.]de:3109.
On the same day, executing the ISO-borne ModiLoader infected a Windows host, retrieved a 4.3 MB base64 payload from OneDrive, and led to Remcos RAT activity. The infected system then initiated TLSv1.3 communications with 146.70.158[.]105:9138 and sent at least 49 MB of outbound data while establishing persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and C:\Users\Public\Libraries.
A malicious email masquerading as a purchase order was received in a honeypot account at 04:14 UTC, carrying an ISO attachment that contained a ModiLoader executable disguised with an Excel icon.
A second YARA rule, win_dbatloader_w0, was created to detect a cryptographic routine associated with win.dbatloader, with metadata listing Daniel Plohmann as author.
A YARA rule named win_dbatloader_auto for detecting the win.dbatloader malware family was autogenerated by yara-signator, with metadata attributing authorship to Felix Bilstein.
VinCSS published a technical analysis of a ModiLoader sample delivered via malspam that used multiple Delphi-based stages, runtime decryption, and in-memory execution to retrieve and launch a final Warzone RAT payload. The analysis also documented persistence through Vwnt.url and Vwntnet.exe in %USERPROFILE%\AppData\Local and a Run key named "Vwnt" under HKCU.
Check Point Research published an analysis of the Warzone RAT malware family in a report titled "Warzone: Behind the enemy lines." This is an earlier documented research milestone for Warzone RAT than the existing timeline entries.
Zscaler described DBatLoader as a Delphi-based loader that uses multilayer obfuscation and image steganography, downloads later stages from cloud services such as OneDrive and Google Drive, and drops files into C:\Users\Public\Libraries. The analysis detailed its Mock Trusted Directories UAC bypass, relative path DLL hijack using easinvoker.exe and netutils.dll, Defender exclusions via PowerShell, and persistence through a .url shortcut and Run key.
Netskope documented a DBatLoader/ModiLoader sample that downloaded its second stage from Discord attachment URLs and ultimately executed an embedded Warzone RAT payload via process hollowing. The sample established persistence by copying itself to %AppData% as "windows explorer.exe" and creating a Windows Registry autorun entry.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourcekienmanowar.wordpress.com
Open sourceisc.sans.edu
Open sourcenetskope.com
Open sourceblog.vincss.net
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.