Skip to content

GuLoader

GuLoader, also known as CloudEyE, is a Windows malware loader and downloader widely used to deliver second-stage commodity malware, particularly remote access trojans and information stealers.

Profile source: Mallory opens in a new tab

GuLoader

Family profile

GuLoader, also known as CloudEyE, is a Windows malware loader and downloader widely used to deliver second-stage commodity malware, particularly remote access trojans and information stealers. It has been observed distributing families including Remcos, FormBook, XLoader, AZORult, Agent Tesla, LokiBot, NanoCore, NetWire, Quasar RAT, Vidar, and related payloads. GuLoader has been linked to broad criminal delivery activity and has been used in campaigns associated with operators such as RATicate; reporting has also connected its use to multiple threat clusters including TA505, TA542, and Gorgon Group.

GuLoader is notable for staging encrypted payloads on legitimate cloud and web services, especially platforms such as Google Drive and OneDrive, then retrieving, decrypting, and executing them in memory. Delivery commonly relies on phishing and malspam, including tax-themed, shipping-themed, invoice-themed, COVID-19-themed, and other business-lure campaigns. Observed infection chains include malicious links, macro-enabled Microsoft Word documents, archive attachments, and documents exploiting CVE-2017-11882. Some campaigns have also used GuLoader as an intermediate stage launched from shortcut-driven or script-based phishing chains.

On execution, GuLoader downloads additional malware over HTTP or via abused cloud-hosted storage, decrypts the payload, and launches it through shellcode execution, process injection, or process hollowing-style techniques. It has been observed injecting into suspended donor processes and using section-mapping-based injection and other native API-heavy execution methods to reduce detection. GuLoader also employs anti-analysis and defense-evasion features, including anti-VM, anti-sandbox, anti-debugging, time-based checks, debugger interference, and attempts to remove or bypass user-mode hooks. Some analyses have documented self-deletion from temporary directories after execution.

Persistence has been observed through Windows RunOnce registry autostart. GuLoader has also been reported using discovery-related API activity and service or product enumeration in some samples, likely to support evasion or execution decisions. The malware’s implementation and packaging have evolved over time, including Visual Basic, NSIS, and .NET variants, while preserving its core role as a flexible malware delivery platform. Its combination of cloud-hosted staging, in-memory execution, and anti-analysis tradecraft has made it a persistent component of phishing-driven Windows malware ecosystems.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 1, 2026
Feed role
C2 / Distribution
Host form
21 IP / 9 hostnames

Leading locations

  • US9
  • SE8
  • LV4
  • DE3
  • NL3
  • FR1
  • MY1
  • ZA1

Leading providers

  • SIA RixHost7
  • HostPapa4
  • SIA RixHost4
  • Hetzner Online GmbH3
  • SIA RixHost2
  • Cloudflare, Inc.1

Infrastructure traits

  • Hosting 29
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
TA505

In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...

TA542

In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...

RATicate

Initially identified (by researchers at CheckPoint) as Guloader, the new Visual Basic 6-based installer was tied to a publicly-marketed installation builder called CloudEyE.

Gorgon APT

In this blog, we will dig deeper into the GuLoader malware which comes attached as a spam document in such emails. This malware is a VBdownloader...

TA558

[☢️Campaign] GuLoader: Using it as a hook to deploy Snake

Storm-0249

Earlier this April, the Redmond-based company warned of several phishing campaigns leveraging tax-related themes to deploy malware such as Latrodectus, AHKBot, GuLoader, and BruteRatel C4 (BRc4). The phishing pages, it added, were delivered via RaccoonO365, with one such campaign attributed to an initial access broker called Storm-0249.

Exploited software

Vulnerabilities linked to GuLoader

4 CVEs

MITRE ATT&CK

GuLoader in ATT&CK

69 distinct techniques

Techniques

69 techniques
T1560 Archive Collected Data T1204 User Execution T1547.001 Registry Run Keys / Startup Folder T1566 Phishing T1059.001 PowerShell T1204.002 Malicious File T1566.002 Spearphishing Link T1129 Shared Modules T1055.002 Portable Executable Injection T1055 Process Injection T1055.001 Dynamic-link Library Injection T1497.001 System Checks T1105 Ingress Tool Transfer T1102 Web Service T1070.004 File Deletion T1071.001 Web Protocols T1106 Native API T1204.001 Malicious Link T1059.005 Visual Basic T1497.003 Time Based Checks T1203 Exploitation for Client Execution T1059 Command and Scripting Interpreter T1071 Application Layer Protocol T1055.012 Process Hollowing T1566.001 Spearphishing Attachment T1622 Debugger Evasion T1562.001 Disable or Modify Tools T1027 Obfuscated Files or Information T1055.009 Proc Memory T1518 Software Discovery T1059.003 Windows Command Shell T1041 Exfiltration Over C2 Channel T1140 Deobfuscate/Decode Files or Information T1564.003 Hidden Window T1620 Reflective Code Loading T1566.003 Spearphishing via Service T1497 Virtualization/Sandbox Evasion T1547.009 Shortcut Modification T1007 System Service Discovery T1218 System Binary Proxy Execution T1027.005 Indicator Removal from Tools T1083 File and Directory Discovery T1562 Impair Defenses T1012 Query Registry T1036 Masquerading T1027.007 Dynamic API Resolution T1197 BITS Jobs T1112 Modify Registry T1027.006 HTML Smuggling T1574 Hijack Execution Flow T1027.002 Software Packing T1132 Data Encoding T1608.001 Upload Malware T1057 Process Discovery T1480 Execution Guardrails T1561 Disk Wipe T1218.011 Rundll32 T1189 Drive-by Compromise T1199 Trusted Relationship T1059.006 Python T1048 Exfiltration Over Alternative Protocol T1583.006 Web Services T1564.001 Hidden Files and Directories T1059.007 JavaScript T1001 Data Obfuscation T1553.002 Code Signing T1036.008 Masquerade File Type T1027.001 Binary Padding T1588.002 Tool

Reporting

Research mentioning GuLoader

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.