Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2
- Host form
- 3 IP / 0 hostnames
DBatLoader is a malware loader observed in phishing-driven intrusion chains and referenced alongside other loaders such as Amadey, DarkGate, and GuLoader.
Profile source: Mallory opens in a new tabDBatLoader
DBatLoader is a malware loader observed in phishing-driven intrusion chains and referenced alongside other loaders such as Amadey, DarkGate, and GuLoader. The provided content places it in campaigns abusing Windows LNK shortcut files and PowerShell-based execution, and notes that PowerShell is used by DBatLoader to evade detection and download additional payloads. DBatLoader has also been mentioned as being deployed alongside other malware, including DarkCloud and ClipBanker, and in a phishing campaign distributing WarZone RAT via DBatLoader. High-confidence details in the content indicate its role is as a loader used to stage or launch follow-on malware rather than as the final payload. The content does not provide specific DBatLoader-exclusive IOCs, persistence mechanisms, or technical internals beyond its association with phishing, LNK abuse, and PowerShell-enabled payload delivery.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.