Skip to main content

Threats Tagged 'python loader'

View all threats tagged with 'python loader'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: python loader

Threats Tagged 'python loader'

Click on any threat for detailed analysis and mitigation recommendations

SynkLoader is a sophisticated modular malware loader that uses multiple programming languages to evade detection. It begins with a Microsoft Teams phishing attack impersonating IT helpdesk staff to trick victims into installing a fake PowerShell cleaner via an MSI installer. The malware operates in memory, using Python, C#, C++, and PowerShell components to profile systems, maintain persistence through scheduled tasks, and deploy a fake Windows lock screen to phish credentials. Additional modules provide reverse proxy capabilities for network tunneling, remote shell, and VNC access, enabling attackers to move laterally and perform hands-on-keyboard operations. The complexity and multi-stage infection chain indicate potential use for ransomware or initial access brokering.

Join the discussion

A sophisticated CHM-based malware campaign has been identified targeting Vietnamese victims through a trojanized CV document. The infection chain utilizes a compiled HTML file that deploys a multi-stage payload delivery mechanism involving Python interpreters, C++ DLLs, and layered XOR encryption. The malware establishes persistence through Shell hijacking and scheduled tasks, ultimately delivering a weaponized version of Rebex.Common.dll functioning as a Telegram-based remote access trojan. The RAT communicates via Telegram bot API, supporting commands for file download, token swapping, and arbitrary command execution. The infection demonstrates characteristics typical of targeted state-sponsored activity rather than opportunistic cybercrime, employing techniques historically associated with advanced threat actors operating in the Southeast Asian region.

Join the discussion

Throughout July and August 2025, TA415, a Chinese state-sponsored threat actor, conducted spearphishing campaigns targeting U.S.government, think tank, and academic organizations focused on U.S.-China relations. The group impersonated high-profile individuals and organizations to deliver an infection chain establishing Visual Studio Code Remote Tunnels for persistent remote access. This activity, likely aimed at gathering intelligence on U.S.-China economic ties, utilized legitimate services like Google Sheets and VS Code for command and control. TA415 employed a Python loader called WhirlCoil to set up the remote tunnels and exfiltrate system information. The targeting pattern and timing suggest evolving priorities shaped by the complex U.S.-China economic relationship.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: python loader
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses