Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 7 IP / 2 hostnames
DBatLoader, also known as ModiLoader and NatsoLoader, is a Windows malware loader written in Delphi that is used to retrieve, decrypt, and execute additional payloads.
Profile source: Mallory opens in a new tabDBatLoader
DBatLoader, also known as ModiLoader and NatsoLoader, is a Windows malware loader written in Delphi that is used to retrieve, decrypt, and execute additional payloads. It has been observed delivering commodity malware families including Warzone RAT, Remcos RAT, NetWire, and Formbook. Delivery commonly begins with phishing lures, including HTML or archive attachments that ultimately launch the loader, and DBatLoader has also been associated with abuse of public cloud and content-hosting services such as OneDrive, Google Drive, and Discord for staging later payloads.
The loader uses multilayer obfuscation and has been documented concealing encrypted second-stage content in resources, including steganographic storage within image data. It decodes payloads in memory and executes them directly, including through shellcode-based staging and process hollowing. Observed samples allocate memory with standard Windows APIs and reconstruct either DLL or executable second stages before transfer of execution.
DBatLoader also incorporates defense-evasion and persistence features. Reported behavior includes use of PowerShell to weaken Microsoft Defender coverage, establishment of autorun persistence in the current user context, and self-copying to user-accessible locations. Some samples abuse User Account Control bypass techniques based on mock trusted directories and relative-path DLL hijacking involving auto-elevated binaries, allowing elevated execution without a normal prompt. Persistence has also been achieved through malicious shortcut-based execution.
The malware is best characterized as a loader rather than the final intrusive payload. Its operational role is to bridge initial access and payload deployment, after which delivered malware may provide remote access, credential theft, or other post-compromise functionality. DBatLoader is part of a broader ecosystem of commodity malware distribution and is notable for flexible staging, in-memory execution, cloud-service abuse, and practical Windows-focused evasion techniques.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e 0128fb60a5557d520ecd0d61f4b442317ff668deef20f9ee64264c20cf299285 174047faedae187b42c666c6c34ba1fdb1791b16f1c63f6bd2258fbd6409b77a 26fc8807ce9a5e6dc534c237d84c2ac7491755532a2078878bc8fb1695fcb2eb eb3fb2f071fbb6e9860c1edf846eb9edb1834928f1193e412941e14a5c7de8fe ecb67ac7512c40c667d6ed853630be084011aa5f857f696aeeeaa1a99bf491bf MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.