Netskope Threat Labs

BanLoad

ATP Sandbox Adv. HeuristicsAV

BanLoad is a Java based downloader used heavily in Brazilian banking fraud campaigns to deliver a wide variety of malware payloads, especially banking trojans. It typically arrives through spam emails and malicious links, and it pulls additional stages from remote servers onto infected systems. The family has circulated for many years, and its operators continually adjust its delivery chains as email defenses improve.

First seen
March 2022
Last seen
October 2026
Banload
Alert Name
Binary.Downloader.BanLoad
ByteCode-JAVA.Downloader.Banload
ByteCode-JAVA.Downloader.BanLoad
ByteCode-JAVA.Exploit.Banload
ByteCode-MSIL.Downloader.Banload
ByteCode-MSIL.Downloader.BanLoad
ByteCode-MSIL.Spyware.Banload
Document-HTML.Downloader.BanLoad
Document-RTF.Downloader.BanLoad
Document-Word.Exploit.Banload