s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.mints_loader

📛 Threat Title

Malware family: MintsLoader

Category: MintsLoader First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.mints_loader`. Printable name: MintsLoader.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:assets.recordedfuture.com

    Recorded Futureʼs Malware Intelligence Hunting provides up-to-date C2 domains and other artifacts related to MintsLoader that would otherwise be hard to track due to its dynamic infrastructure. Insikt Group shows that GhostWeaver is the primary payload deployed by MintsLoader across observed campaigns.

  • web:blackpointcyber.com

    Here's how a recent Fake Captcha campaign leveraged the Finger protocol to deliver a MintsLoader variant using Hashtable-based obfuscation.

  • web:cybernoz.com

    The malware loader known as MintsLoader has been used to deliver a PowerShell-based remote access trojan called GhostWeaver. " MintsLoader operates through a multi-stage infection chain involving obfuscated JavaScript and PowerShell scripts," Recorded Future's Insikt Group said in a report shared with The Hacker News. "The malware employs sandbox and virtual machine evasion techniques ...

  • web:ec2-3-226-136-182.compute-1.amazonaws.com

    MintsLoader delivers GhostWeaver via phishing while ClickFix leverages DGA and TLS to execute stealth cyber attacks.

  • web:github.com

    TA582 is tracked by some vendors in relation to malspam and commodity malware distribution. While the primary attribution in this investigation points to TAG-124 / MintsLoader , the #ta582 tag suggests potential overlap or shared tooling between these clusters — consistent with MintsLoader's documented use as a shared loader across multiple ...

  • web:itsecuritynewsbox.com

    If the target passes the checks, the loader downloads advanced malware like GhostWeaver, a PowerShell-based RAT with TLS-encrypted C2 communication and capabilities to redeploy MintsLoader . If the system fails validation, the C2 may deliver a decoy executable like AsyncRAT, which has led to misclassifications in threat reports.

  • web:news.backbox.org

    January 27, 2025/in General News Threat hunters have detailed an ongoing campaign that leverages a malware loader called MintsLoader to distribute secondary payloads such as the StealC information stealer and a legitimate open-source network computing platform called BOINC. " MintsLoader is a PowerShell based malware loader that has been seen delivered via spam emails with a link to Kongtuke ...

  • web:securitricks.com

    Various threat groups, including TAG-124 and SocGholish operators, utilize MintsLoader to target industrial, legal, and energy sectors. The loader's sophisticated obfuscation and evasion methods complicate detection, but Recorded Future's Malware Intelligence Hunting provides up-to-date information on new samples and C2 domains.

  • web:techinvestornews.io

    Threat hunters have detailed an ongoing campaign that leverages a malware loader called MintsLoader to distribute secondary payloads such as the StealC information stealer and a legitimate open-source network computing platform called BOINC. " MintsLoader is a PowerShell based malware loader that has been seen delivered via spam emails with a link to Kongtuke/ClickFix pages or a JScript file,"

  • web:thehackernews.com

    Threat hunters have detailed an ongoing campaign that leverages a malware loader called MintsLoader to distribute secondary payloads such as the StealC information stealer and a legitimate open-source network computing platform called BOINC. " MintsLoader is a PowerShell based malware loader that has ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.