<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Malware-Loader on CuraSec</title><link>https://curasec.metacog.co.kr/tags/malware-loader/</link><description>Recent content in Malware-Loader on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 04 Aug 2026 13:07:50 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/malware-loader/index.xml" rel="self" type="application/rss+xml"/><item><title>DOUBLECUP LaaS Uses ClickFix and PNG Steganography to Drop RAT</title><link>https://curasec.metacog.co.kr/insights/2026-08-04-doublecup-uses-clickfix-and-cached-pngs-to-deliver-countload/</link><pubDate>Tue, 04 Aug 2026 13:07:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-04-doublecup-uses-clickfix-and-cached-pngs-to-deliver-countload/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel multi-stage delivery abusing browser cache for steganographic PNG staging is worth understanding when evaluating endpoint controls and browser security policies, but no patch or configuration change is required today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for ClickFix PowerShell execution patterns and anomalous PNG writes to browser cache directories; the CountLoader → DeviceManager RAT chain provides new TTPs to add to hunt playbooks this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>China-Nexus JadeProx Deploys New TriBack Loader Against Gov/Healthcare</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-china-nexus-jadeprox-uses-new-triback-loader-in-government-a/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-china-nexus-jadeprox-uses-new-triback-loader-in-government-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> A newly documented Windows loader from a China-nexus cluster, but no specific vulnerable software, patch, or configuration action is identified — useful for understanding adversary tradecraft in government and healthcare environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Group-IB&amp;rsquo;s exposure of the JadeProx cluster and TriBack Loader provides actor-profile and malware-family context, but the summary lacks published IOCs or ATT&amp;amp;CK-mapped TTPs needed to build or tune detections immediately.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> China-nexus targeting of government and healthcare sectors in Asia and Latin America is worth tracking for sector-risk awareness, but no vendor breach or imminent regulatory trigger warrants same-week leadership action.&lt;/li>
&lt;/ul></description></item></channel></rss>