TF-MAL-js.mints_loader
📛 Threat Title
Malware family: MintsLoader
Description
ThreatFox malware family `js.mints_loader`. Printable name: MintsLoader.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:assets.recordedfuture.com
Recorded Futureʼs Malware Intelligence Hunting provides up-to-date C2 domains and other artifacts related to MintsLoader that would otherwise be hard to track due to its dynamic infrastructure. Insikt Group shows that GhostWeaver is the primary payload deployed by MintsLoader across observed campaigns.
-
web:blackpointcyber.com
Here's how a recent Fake Captcha campaign leveraged the Finger protocol to deliver a MintsLoader variant using Hashtable-based obfuscation.
-
web:cybernoz.com
The malware loader known as MintsLoader has been used to deliver a PowerShell-based remote access trojan called GhostWeaver. " MintsLoader operates through a multi-stage infection chain involving obfuscated JavaScript and PowerShell scripts," Recorded Future's Insikt Group said in a report shared with The Hacker News. "The malware employs sandbox and virtual machine evasion techniques ...
-
web:ec2-3-226-136-182.compute-1.amazonaws.com
MintsLoader delivers GhostWeaver via phishing while ClickFix leverages DGA and TLS to execute stealth cyber attacks.
-
web:github.com
TA582 is tracked by some vendors in relation to malspam and commodity malware distribution. While the primary attribution in this investigation points to TAG-124 / MintsLoader , the #ta582 tag suggests potential overlap or shared tooling between these clusters — consistent with MintsLoader's documented use as a shared loader across multiple ...
-
web:itsecuritynewsbox.com
If the target passes the checks, the loader downloads advanced malware like GhostWeaver, a PowerShell-based RAT with TLS-encrypted C2 communication and capabilities to redeploy MintsLoader . If the system fails validation, the C2 may deliver a decoy executable like AsyncRAT, which has led to misclassifications in threat reports.
-
web:news.backbox.org
January 27, 2025/in General News Threat hunters have detailed an ongoing campaign that leverages a malware loader called MintsLoader to distribute secondary payloads such as the StealC information stealer and a legitimate open-source network computing platform called BOINC. " MintsLoader is a PowerShell based malware loader that has been seen delivered via spam emails with a link to Kongtuke ...
-
web:securitricks.com
Various threat groups, including TAG-124 and SocGholish operators, utilize MintsLoader to target industrial, legal, and energy sectors. The loader's sophisticated obfuscation and evasion methods complicate detection, but Recorded Future's Malware Intelligence Hunting provides up-to-date information on new samples and C2 domains.
-
web:techinvestornews.io
Threat hunters have detailed an ongoing campaign that leverages a malware loader called MintsLoader to distribute secondary payloads such as the StealC information stealer and a legitimate open-source network computing platform called BOINC. " MintsLoader is a PowerShell based malware loader that has been seen delivered via spam emails with a link to Kongtuke/ClickFix pages or a JScript file,"
-
web:thehackernews.com
Threat hunters have detailed an ongoing campaign that leverages a malware loader called MintsLoader to distribute secondary payloads such as the StealC information stealer and a legitimate open-source network computing platform called BOINC. " MintsLoader is a PowerShell based malware loader that has ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.