Netskope Threat Labs

GuLoader

ATP Sandbox Adv. HeuristicsAV

GuLoader is a small downloader that delivers remote access trojans and infostealers such as AgentTesla, FormBook, and Remcos to infected systems. It arrives through phishing emails and malvertising chains, and it uses the CloudEye panel for command and control, which ties its many campaigns to a shared commercial ecosystem. The loader changes its code structure frequently to frustrate signature detection, and its operators sell it as a service to other criminal crews.

First seen
March 2022
Last seen
October 2026
GULoaderGuloader

12 techniques across 5 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Trojan.GuLoader
Document-Excel.Trojan.Guloader
Document-RTF.Trojan.GuLoader
Email-MIME.Downloader.Guloader
Email-MIME.Trojan.Guloader
Email-MIME.Trojan.GuLoader
Email-MSG.Trojan.Guloader
Email-MSG.Trojan.GuLoader
Email.Trojan.Guloader
GT:VB.Guloader.2.02E645A8