Loader
CoffeeLoader
Zscaler ThreatLabz states that this sophisticated malware family likely originated around September 2024.
CoffeeLoader is a Windows loader.
Background
Zscaler ThreatLabz assesses that this advanced malware family most likely emerged around September 2024. Its role is to fetch and run second-stage payloads while slipping past endpoint security products. To defeat defenses it employs a range of methods, including a dedicated GPU-based packer named Armoury, call stack spoofing, sleep obfuscation, and Windows fibers. It also ships with a fallback DGA and can deliver Rhadamanthys shellcode. ThreatLabz has seen CoffeeLoader spread through SmokeLoader, and the two families exhibit some shared behavioral traits.
Source: Malpedia (Fraunhofer FKIE).