Categories: Cyber Security News

QuirkyLoader – The New Malware Loader Spreading Infostealers and Remote Access Trojans

Cybersecurity researchers at IBM X-Force have identified a sophisticated new malware loader dubbed QuirkyLoader that has been actively distributing notorious malware families, including Agent Tesla, AsyncRAT, FormBook, MassLogger, Remcos, Rhadamanthys, and Snake Keylogger since November 2024.

This multi-stage threat demonstrates advanced evasion techniques and targets victims through carefully crafted email campaigns containing malicious archives.

Advanced DLL Side-Loading Technique Evades Detection

QuirkyLoader employs a sophisticated infection chain that begins when victims open malicious archive files attached to spam emails.

The archive contains three critical components: a legitimate executable, an encrypted payload disguised as a DLL, and a malicious DLL loader module.

The threat actors leverage DLL side-loading, a technique where executing the legitimate executable automatically loads the malicious DLL alongside it.

What makes QuirkyLoader particularly concerning is its use of ahead-of-time (AOT) compilation for its .NET-based DLL modules.

This process compiles C# code directly into native machine code, bypassing the traditional .NET compilation method and making the resulting binary appear as though it were written in C or C++.

This technique effectively disguises the malware’s true nature from security tools designed to detect .NET assemblies.

The malware demonstrates technical sophistication in its decryption methods, with one variant utilizing the rarely-seen Speck-128 cipher with Counter mode to decrypt payloads.

Once decrypted, QuirkyLoader performs process hollowing on legitimate Windows processes, including AddInProcess32.exe, InstallUtil.exe, or aspnet_wp.exe, to inject the final malicious payload.

Targeted Campaigns Hit Taiwan and Mexico

Recent campaigns observed in July 2025 revealed QuirkyLoader’s targeted approach. In Taiwan, threat actors specifically targeted employees of Nusoft Taiwan, a network and internet security research company, distributing Snake Keylogger infostealer.

Meanwhile, a separate campaign in Mexico randomly targeted individuals with both Remcos RAT and AsyncRAT payloads.

IBM X-Force’s investigation uncovered related network infrastructure centered around the domain catherinereynolds[.]info, which resolves to IP address 157[.]66[.]225[.]11 and hosts a Zimbra web client. Further analysis revealed additional related IP addresses sharing similar SSL certificates and hosting configurations.

Mitigation Strategies Critical for Defense

Security experts recommend that organizations implement several defensive measures against QuirkyLoader threats.

These include blocking emails with executable attachments, avoiding unexpected email attachments from untrusted sources, and maintaining updated security configurations.

Given that final payloads typically consist of infostealers and remote access tools, organizations should actively monitor outbound network traffic and closely observe the behavior of commonly targeted legitimate processes that QuirkyLoader exploits for process hollowing.

The emergence of QuirkyLoader represents a significant evolution in malware delivery techniques, combining legitimate tools with advanced compilation methods to evade detection while distributing established threat families.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post QuirkyLoader – The New Malware Loader Spreading Infostealers and Remote Access Trojans appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Resident Evil Requiem Players Miss the Merchant from RE4 So Much That Someone Made a Mod to Add Him to the Game

Resident Evil Requiem players were sad to see the Merchant left out of Leon's latest…

5 hours ago

Bungie Confirms It Has Marathon Story Plans for ‘the Next Few Years’ But Nothing Is Completely ‘Locked in’ Yet

It looks like Marathon won’t be left behind anytime soon, as Bungie has confirmed it…

6 hours ago

The Best Deals Today: Yakuza Kiwami 3 & Dark Ties, Superman 4K Steelbook Collection, Suzume Blu-ray, and More

A new weekend has arrived, and today, you can save big on Yakuza Kiwami 3…

7 hours ago

The Best Deals Today: Yakuza Kiwami 3 & Dark Ties, Superman 4K Steelbook Collection, Suzume Blu-ray, and More

A new weekend has arrived, and today, you can save big on Yakuza Kiwami 3…

7 hours ago

Microsoft Defender Mistakenly Flags DigiCert Root Certificates as Malware

Microsoft Defender triggered widespread false positive alerts after a faulty security update caused it to…

7 hours ago

Marvel Tokon: Fighting Souls Confirms Savage Hulk and Shuri Black Panther as Playable Fighters as Fans Spot Hidden Carnage Tease

Developer Arc System Works has confirmed that Hulk and Black Panther have joined the roster…

8 hours ago

This website uses cookies.