KongTuke has also been seen using a wider kit, including WinPython, Node.js, finger.exe, a fake NexShield browser extension, the encrypted GateKeeper .NET payload, and loaders like MintsLoader and D3F@ck Loader.
MintsLoader
MintsLoader is a multi-stage malware loader active since at least 2023 and widely observed in campaigns from 2024 onward.
Profile source: Mallory opens in a new tabMintsLoader
Family profile
MintsLoader is a multi-stage malware loader active since at least 2023 and widely observed in campaigns from 2024 onward. It is primarily a Windows-focused delivery platform implemented through JavaScript and PowerShell stages, and is used to fetch and execute follow-on payloads rather than provide extensive standalone post-compromise functionality of its own. Reported second-stage payloads include GhostWeaver, StealC, Vidar, AsyncRAT, and modified BOINC clients, with some campaigns using decoy payloading to frustrate analysis.
The loader is associated with financially motivated intrusion activity and has been linked to operators tracked as TAG-124, LandUpdate808, and UNC4108. It has also been observed in broader criminal delivery ecosystems involving KongTuke and SocGholish, where compromised websites, fake update lures, and ClickFix-style social engineering are used to drive victims into the infection chain. MintsLoader has been seen in phishing campaigns using invoice-themed lures and in spam-driven delivery chains targeting organizations in the United States and Europe, including the energy, industrial, and legal sectors.
Its infection flow commonly begins with a malicious JavaScript or JScript stage that launches obfuscated PowerShell. Subsequent stages retrieve additional code from attacker-controlled infrastructure, often using domain generation algorithms to rotate command-and-control endpoints. MintsLoader employs multiple anti-analysis and defense-evasion measures, including AMSI bypass attempts, virtual-machine and sandbox checks, and host-environment scoring based on WMI-derived system characteristics such as virtualization indicators, GPU properties, and CPU cache information. In some observed operations, these checks are used to withhold the real payload from likely analysis environments and instead return alternate content.
MintsLoader is notable for its role as a stealthy staging mechanism in larger intrusion chains. It has been used to deliver both information stealers and remote-access tooling, and in some ecosystems appears closely integrated with downstream malware such as GhostWeaver. Its operational use across phishing, ClickFix, and fake-update web compromises makes it a flexible commodity loader within the contemporary cybercrime access-and-delivery market.
Capabilities
- Defense Evasion
- Initial Access
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
6 named in public reportingKongTuke has also been seen using a wider kit, including WinPython, Node.js, finger.exe, a fake NexShield browser extension, the encrypted GateKeeper .NET payload, and loaders like MintsLoader and D3F@ck Loader.
MintsLoader (TAG-124 / LandUpdate808 / UNC4108) Type: Malware Loader - PowerShell-based, multi-stage delivery platform
Another recently observed customer of TA569 is the MintsLoader malware family... UNC4108 utilizes MintsLoader to deploy various payloads...
Before the RAT arrives, a profiler called MintsLoader runs three checks on the target machine... When we submitted the delivery URLs to a sandbox, the server connected but withheld the payload.
Loaders like Latrodectus and MintsLoader, which could deliver additional malware and other payloads
MITRE ATT&CK
MintsLoader in ATT&CK
29 distinct techniquesTechniques
29 techniquesReporting
Research mentioning MintsLoader
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.