Skip to content
Malware family

MintsLoader

MintsLoader is a PowerShell-based, multi-stage malware loader, also tracked in the provided content as TAG-124, LandUpdate808, and UNC4108.

Profile source: Mallory opens in a new tab

MintsLoader

Family profile

MintsLoader is a PowerShell-based, multi-stage malware loader, also tracked in the provided content as TAG-124, LandUpdate808, and UNC4108. It has been observed since at least February 2023 and became more widespread from mid-2024 onward. The malware affects Windows endpoints and is used to stage follow-on payloads rather than provide extensive standalone functionality.

The reported delivery chains include multi-stage JavaScript-to-PowerShell execution, phishing attachments, ClickFix-style social engineering, and compromised-website delivery via SocGholish/FakeUpdates. Observed phishing lures included invoice-themed campaigns, including JScript attachments such as Italian invoice-themed files. ClickFix and KongTuke-related lures instructed victims to paste commands into the Windows Run dialog, including abuse of the legitimate Microsoft-signed finger.exe LOLBin to retrieve and execute additional stages. SocGholish has also been observed delivering MintsLoader through fake browser update overlays on compromised websites.

Capabilities and behavior described in the content include AMSI bypass, arithmetic and hashtable-based string obfuscation, reflective loading of Base64-encoded Gzip-compressed .NET assemblies, WMI-based anti-sandbox and environment scoring, and use of multiple domain generation algorithms, including date-seeded DGA logic, to resolve command-and-control infrastructure. The malware selectively withholds real payloads from sandbox or virtualized environments and may instead deliver decoy payloads such as AsyncRAT. Researchers also reported daily-changing C2 domains and more than 200 DGA domains across multiple clusters.

MintsLoader is primarily associated with delivery of GhostWeaver, a PowerShell RAT, and the content describes GhostWeaver as tightly integrated with MintsLoader, including cases where MintsLoader profiles targets before GhostWeaver deployment. Additional payloads mentioned in the content include StealC, modified BOINC clients, LockBit, RansomHub, AsyncRAT, NetSupport RAT, and in some reporting Broomstick or WarmCookie. Orange Cyberdefense observed SocGholish infections delivering loaders such as MintsLoader that led to GhostWeaver, LockBit, RansomHub, AsyncRAT, and NetSupport RAT.

The malware is linked in the content to multiple threat actors and ecosystems. TAG-124/LandUpdate808 is identified as the primary sustained operator. SocGholish/TA569 is described as an early adopter that used MintsLoader as an alternative delivery chain around July 2024. KongTuke is also reported to use MintsLoader among other loaders and tooling, and TA582 is described as using MintsLoader to score targets before delivering GhostWeaver to real machines while serving decoys to sandboxes.

Targeting described in the content includes industrial, legal, and energy organizations in the United States and Europe. High-confidence infrastructure details directly mentioned include active C2 clusters at 178.156.128.182 and 86.107.101.93, and observed delivery-related domains or hosts such as humver[.]top, cfcheckver[.]top, and 91.193.19[.]108 in ClickFix activity. The content also notes that experts shared up-to-date C2 domains and other artifacts related to recent MintsLoader attacks.

Observed infrastructure

Last seven days

First activity
Jul 20, 2026
Last activity
Jul 20, 2026
Feed role
Distribution
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • BL Networks1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
KongTuke

KongTuke has also been seen using a wider kit, including WinPython, Node.js, finger.exe, a fake NexShield browser extension, the encrypted GateKeeper .NET payload, and loaders like MintsLoader and D3F@ck Loader.

Woodgnat

KongTuke has also been seen using a wider kit, including WinPython, Node.js, finger.exe, a fake NexShield browser extension, the encrypted GateKeeper .NET payload, and loaders like MintsLoader and D3F@ck Loader.

Indrik Spider

MintsLoader (TAG-124 / LandUpdate808 / UNC4108) Type: Malware Loader - PowerShell-based, multi-stage delivery platform

SocGholish

MintsLoader (TAG-124 / LandUpdate808 / UNC4108) Type: Malware Loader - PowerShell-based, multi-stage delivery platform

UNC4108

Another recently observed customer of TA569 is the MintsLoader malware family... UNC4108 utilizes MintsLoader to deploy various payloads...

TA582

Before the RAT arrives, a profiler called MintsLoader runs three checks on the target machine... When we submitted the delivery URLs to a sandbox, the server connected but withheld the payload.

Storm-0426

Loaders like Latrodectus and MintsLoader, which could deliver additional malware and other payloads

MITRE ATT&CK

MintsLoader in ATT&CK

24 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.