MosaicLoader Spreads RATs and Infostealers

Top 5 Identity Theft Risks

Malware researchers have identified a new strain of malware, which goes under the name MosaicLoader. The threat is able to distribute additional payloads to its victims, and it has been typically used in combination with Remote Access Trojans (RATs) or information stealers. The MosaicLoader Malware is being distributed with the help of malicious advertisements, phishing emails, and even cracked software or games. Needless to say, one way to protect your system from such intrusions is to use an up-to-date anti-malware application, as well as to be more careful with the online content you interact with.

Trojan Loaders like MosaicLoader can be extremely dangerous because they are very flexible in terms of the payloads they deliver. The operators of this particular Trojan appear to experiment with a wide range of implants, therefore allowing them to fine-tune their attacks and enhance the profitability of the campaign. Similar Trojan Loaders are the JSSLoader and Campo Loader.

MosaicLoader's Operators are Interested in Hijacking Facebook Profiles

Although RATs and information stealers appear to be MosaicLoader Malware's primary focus, the criminals were also observed to use a Facebook cookie stealer. This type of malware aims to hijack Facebook accounts and then use them to create posts that either spread malware or scam people. 

Once planted, the MosaicLoader Malware will run in the background continuously. It can conceal its processes and components as part of a legitimate driver package, such as the ones used by NVIDIA hardware, for example. The way that the malware loads additional payloads is also interesting. It fetches a text-file with the URLs of the payloads to download. Some of those are hosted on dedicated sites controlled by criminals, while others are Discord URLs. '

Now that you know what tricks and techniques the criminals behind this campaign used to approach their victims, you can stay away from the suspicious online content. Avoiding torrent trackers completely is recommended – if you decide to browse those, you need to be protected by reputable antivirus software.

July 21, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.