Blog | G5 Cyber Security

Malspam campaign caught using GuLoader after service relaunch

GuLoader is a downloader used by threat actors to distribute malware on a large scale. In June, CloudEye was exposed by CheckPoint as the entity behind GuLoader. CloudEye is a Visual Basic 6 downloader that leverages cloud services to store and retrieve the final piece of software (in the form of heavily obfuscated shellcode) a customer wants to install. GuLoader/CloudEye has proved to be very effective at bypassing sandboxes and security products including network-based detection.”]

Source: https://blog.malwarebytes.com/threat-analysis/2020/07/malspam-campaign-caught-using-guloader-after-service-relaunch/

Exit mobile version