Skip to content

DBatLoader

DBatLoader, also known as ModiLoader and NatsoLoader, is a Windows malware loader written in Delphi that is used to retrieve, decrypt, and execute additional payloads.

Profile source: Mallory opens in a new tab

DBatLoader

Family profile

DBatLoader, also known as ModiLoader and NatsoLoader, is a Windows malware loader written in Delphi that is used to retrieve, decrypt, and execute additional payloads. It has been observed delivering commodity malware families including Warzone RAT, Remcos RAT, NetWire, and Formbook. Delivery commonly begins with phishing lures, including HTML or archive attachments that ultimately launch the loader, and DBatLoader has also been associated with abuse of public cloud and content-hosting services such as OneDrive, Google Drive, and Discord for staging later payloads.

The loader uses multilayer obfuscation and has been documented concealing encrypted second-stage content in resources, including steganographic storage within image data. It decodes payloads in memory and executes them directly, including through shellcode-based staging and process hollowing. Observed samples allocate memory with standard Windows APIs and reconstruct either DLL or executable second stages before transfer of execution.

DBatLoader also incorporates defense-evasion and persistence features. Reported behavior includes use of PowerShell to weaken Microsoft Defender coverage, establishment of autorun persistence in the current user context, and self-copying to user-accessible locations. Some samples abuse User Account Control bypass techniques based on mock trusted directories and relative-path DLL hijacking involving auto-elevated binaries, allowing elevated execution without a normal prompt. Persistence has also been achieved through malicious shortcut-based execution.

The malware is best characterized as a loader rather than the final intrusive payload. Its operational role is to bridge initial access and payload deployment, after which delivered malware may provide remote access, credential theft, or other post-compromise functionality. DBatLoader is part of a broader ecosystem of commodity malware distribution and is notable for flexible staging, in-memory execution, cloud-service abuse, and practical Windows-focused evasion techniques.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Initial Access
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Sep 3, 2026
Feed role
C2 / Distribution
Host form
7 IP / 2 hostnames

Leading locations

  • US4
  • HK2
  • CH1
  • GB1
  • SG1

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • DEDIK SERVICES LIMITED1
  • Google LLC1
  • Hong Kong Communications International Co., Limited1
  • HostPapa1

Infrastructure traits

  • Hosting 6

Samples

Recent associated samples

MITRE ATT&CK

DBatLoader in ATT&CK

20 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.