Skip to content

Loader

CoffeeLoader

Zscaler ThreatLabz states that this sophisticated malware family likely originated around September 2024.

CoffeeLoader is a Windows loader.

Background

Zscaler ThreatLabz assesses that this advanced malware family most likely emerged around September 2024. Its role is to fetch and run second-stage payloads while slipping past endpoint security products. To defeat defenses it employs a range of methods, including a dedicated GPU-based packer named Armoury, call stack spoofing, sleep obfuscation, and Windows fibers. It also ships with a fallback DGA and can deliver Rhadamanthys shellcode. ThreatLabz has seen CoffeeLoader spread through SmokeLoader, and the two families exhibit some shared behavioral traits.


Source: Malpedia (Fraunhofer FKIE).