Executive Summary
GuLoader is a Windows file downloader that serves as a versatile dropper for several high‑profile RATs. By quietly retrieving and executing payloads from remote servers, it expands an attacker’s reach while remaining difficult to detect. Security teams should treat GuLoader as part of broader supply‑chain compromise efforts.
Enhanced Description
GuLoader is a sophisticated Windows-based file downloader that has been operational since at least December 2019. It functions primarily as a delivery mechanism for a range of remote administration tools (RATs) such as NETWIRE, Agent Tesla, NanoCore, FormBook, and Parallax RAT. The tool autonomously retrieves additional malware binaries from command‑and‑control servers or file shares, then executes them locally to establish persistence and expand the adversary’s foothold. Throughout its lifecycle, GuLoader has been observed using stealthy download techniques that leverage legitimate protocol agents (e.g., PowerShell, WMI) and encrypted payloads to evade detection. The distribution chain typically begins with a compromised website or phishing attachment, after which GuLoader silently downloads the payload without user interaction, reducing the chance of discovery by endpoint users. Impact-wise, GuLoader enables attackers to quickly roll out diverse RAT families across enterprise environments. Once executed, these tools can exfiltrate credentials, capture screen images, perform lateral movement, and maintain long‑term persistence, effectively turning infected hosts into command nodes for larger supply‑chain or credential‑stealing campaigns. Overall, GuLoader represents a modular delivery architecture that amplifies the effectiveness of well‑known RATs, making it a valuable asset in any adversary’s toolset.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information originates from reputable sources such as Unit 42 and a Medium publication, providing good basis for the described delivery functionality. However, lacking detailed source code analysis limits insight into evasion tactics, persistence mechanisms, and exact command‑and‑control protocols. Confidence is moderate; further lab reverse engineering and network traffic capture are needed to fill existing gaps.
GuLoader is a file downloader that has been used since at least December 2019 to distribute a variety of remote administration tool (RAT) malware, including NETWIRE, Agent Tesla, NanoCore, FormBook, and Parallax RAT.(Citation: Unit 42 NETWIRE April 2020)(Citation: Medium Eli Salem GuLoader April 2021)