Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 1, 2026
- Feed role
- C2 / Distribution
- Host form
- 21 IP / 9 hostnames
GuLoader, also known as CloudEyE, is a Windows malware loader and downloader widely used to deliver second-stage commodity malware, particularly remote access trojans and information stealers.
Profile source: Mallory opens in a new tabGuLoader
GuLoader, also known as CloudEyE, is a Windows malware loader and downloader widely used to deliver second-stage commodity malware, particularly remote access trojans and information stealers. It has been observed distributing families including Remcos, FormBook, XLoader, AZORult, Agent Tesla, LokiBot, NanoCore, NetWire, Quasar RAT, Vidar, and related payloads. GuLoader has been linked to broad criminal delivery activity and has been used in campaigns associated with operators such as RATicate; reporting has also connected its use to multiple threat clusters including TA505, TA542, and Gorgon Group.
GuLoader is notable for staging encrypted payloads on legitimate cloud and web services, especially platforms such as Google Drive and OneDrive, then retrieving, decrypting, and executing them in memory. Delivery commonly relies on phishing and malspam, including tax-themed, shipping-themed, invoice-themed, COVID-19-themed, and other business-lure campaigns. Observed infection chains include malicious links, macro-enabled Microsoft Word documents, archive attachments, and documents exploiting CVE-2017-11882. Some campaigns have also used GuLoader as an intermediate stage launched from shortcut-driven or script-based phishing chains.
On execution, GuLoader downloads additional malware over HTTP or via abused cloud-hosted storage, decrypts the payload, and launches it through shellcode execution, process injection, or process hollowing-style techniques. It has been observed injecting into suspended donor processes and using section-mapping-based injection and other native API-heavy execution methods to reduce detection. GuLoader also employs anti-analysis and defense-evasion features, including anti-VM, anti-sandbox, anti-debugging, time-based checks, debugger interference, and attempts to remove or bypass user-mode hooks. Some analyses have documented self-deletion from temporary directories after execution.
Persistence has been observed through Windows RunOnce registry autostart. GuLoader has also been reported using discovery-related API activity and service or product enumeration in some samples, likely to support evasion or execution decisions. The malware’s implementation and packaging have evolved over time, including Visual Basic, NSIS, and .NET variants, while preserving its core role as a flexible malware delivery platform. Its combination of cloud-hosted staging, in-memory execution, and anti-analysis tradecraft has made it a persistent component of phishing-driven Windows malware ecosystems.
C2 tracking
Derp observations, rolling seven-day window
Samples
174047faedae187b42c666c6c34ba1fdb1791b16f1c63f6bd2258fbd6409b77a 26fc8807ce9a5e6dc534c237d84c2ac7491755532a2078878bc8fb1695fcb2eb 3887395028e30411080d16dc5ebcd884356ce4c3ed056bbf3d1a07053ccdb5c9 5a03915bd82ebfd94d1009a506158cff27daecdb67ef2acf1c23db481472f718 b4750e372bc14d6f6e4d2281d09c55a392d54a0abc71893c09c9c50b3390bd59 45638f045a1b11236613a326183ea40d7e3652c16eb2ad81c7a697c5adab60bd 968b715acabde7d49a5e0c1081443e5bc335d9647f19cc93bf6c3ebc9384a155 1c3b40e16baa8378b035a428da10fd16fdd13da968c4222325d9bd72eb34b736 2ae721da37efda736a87729b9f730689053632df39068361d556eddd52fc1f28 401883ee8334db650bbd0363335ee46a35492ef1842261341cd1f737f091678a Reported operators
In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
Initially identified (by researchers at CheckPoint) as Guloader, the new Visual Basic 6-based installer was tied to a publicly-marketed installation builder called CloudEyE.
In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...
[☢️Campaign] GuLoader: Using it as a hook to deploy Snake
Earlier this April, the Redmond-based company warned of several phishing campaigns leveraging tax-related themes to deploy malware such as Latrodectus, AHKBot, GuLoader, and BruteRatel C4 (BRc4). The phishing pages, it added, were delivered via RaccoonO365, with one such campaign attributed to an initial access broker called Storm-0249.
Exploited software
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.