All malware guidance

Explainer

Loaders

Small first-stage malware that gets a foothold, profiles the victim and delivers the next payload, often a stealer, remote access tool or ransomware.

In this section

What it is

A loader, sometimes called a dropper or initial access malware, is a lightweight program whose main job is to get onto a machine, stay there and fetch other malware. Loaders are usually sold or rented as a service, and their operators often sell the resulting access to other criminals. Europol and Eurojust describe these families as tools that pave the way for ransomware.

How it gets in

Common delivery routes include phishing emails with malicious attachments or links, malicious search ads, and hacked websites. SocGholish, for example, spreads through fake browser updates shown on compromised websites, according to Eurojust. Amadey is spread via phishing, Eurojust said. The user usually has to run a script or installer, which is why script hosts and download folders are good places to watch.

What it does

After running, a loader typically sets up persistence, collects basic information about the host and network, and checks in with its control server. The operator then decides what to deliver next based on the victim: an infostealer for a home user, or a remote access tool and post-exploitation kit for a machine joined to a corporate domain.

Notable families in 2025-2026

Operation Endgame has repeatedly targeted this layer. In May 2025, The Hacker News reported, authorities took down about 300 servers and neutralised 650 domains linked to Bumblebee, Latrodectus, QakBot, HijackLoader, DanaBot, TrickBot and Warmcookie, and issued 20 international arrest warrants. In June 2026, Eurojust said a further action neutralised 326 servers and 142 domains tied to SocGholish, Amadey and the StealC infostealer.

Disruption changes attacker behaviour. Proofpoint reported in 2025 that activity from several major initial access brokers dropped after Endgame, while more criminals began sending legitimate remote management tools as the first payload instead.

How it is used downstream

Loader access is a commodity. Operators run infections at scale, then sell or hand the most valuable footholds, typically corporate machines, to ransomware affiliates or data-theft crews. Stopping a loader early is one of the cheapest ways to prevent a ransomware incident weeks later. CISA's ransomware guide lists precursor malware such as QakBot and Bumblebee among the common routes into ransomware attacks, which is why loader alerts deserve the same urgency as an encryption alert.

Detect and contain

Detection signals

  • Script hosts (wscript, mshta, PowerShell) launched from browser downloads or archive files
  • Fake browser-update pages in web proxy logs
  • Outbound beacons at fixed intervals to newly registered domains

Reduce the blast radius

  • Application allow-listing on high-value hosts
  • Block script execution from user download and temp folders, and open scripts in Notepad by default
  • DNS filtering for newly registered and uncategorised domains

Questions people ask

What is a malware loader?

A loader is small malware whose job is to establish a foothold on a computer and then download and run other malware, such as infostealers, remote access tools or ransomware. Loaders are usually rented as a service, and their operators often sell access to infected corporate machines to other criminal groups.

What is the difference between a loader and a dropper?

The terms overlap. A dropper usually carries its next payload inside itself and writes it to disk, while a loader typically downloads the next stage from a remote server after checking in. In practice many security vendors use loader for both, because modern families mix the two techniques and focus on delivering whatever the operator chooses.

What is SocGholish?

SocGholish is a long-running loader spread through fake browser update prompts shown on compromised websites. Visitors who run the fake update give attackers a foothold that can be sold on or used to deliver further malware. It was among the families targeted by the June 2026 phase of Operation Endgame, according to Eurojust.

Further reading