Skip to content

DBatLoader

DBatLoader is a malware loader observed in phishing-driven intrusion chains and referenced alongside other loaders such as Amadey, DarkGate, and GuLoader.

Profile source: Mallory opens in a new tab

DBatLoader

Family profile

DBatLoader is a malware loader observed in phishing-driven intrusion chains and referenced alongside other loaders such as Amadey, DarkGate, and GuLoader. The provided content places it in campaigns abusing Windows LNK shortcut files and PowerShell-based execution, and notes that PowerShell is used by DBatLoader to evade detection and download additional payloads. DBatLoader has also been mentioned as being deployed alongside other malware, including DarkCloud and ClipBanker, and in a phishing campaign distributing WarZone RAT via DBatLoader. High-confidence details in the content indicate its role is as a loader used to stage or launch follow-on malware rather than as the final payload. The content does not provide specific DBatLoader-exclusive IOCs, persistence mechanisms, or technical internals beyond its association with phishing, LNK abuse, and PowerShell-enabled payload delivery.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 6, 2026
Feed role
C2
Host form
3 IP / 0 hostnames

Leading locations

  • US2
  • HK1

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • XNNET LLC1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

MITRE ATT&CK

DBatLoader in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.