Netskope Threat Labs

Sadbridge

ATP Sandbox Adv. Heuristics

Sadbridge is a malware loader packaged as an MSI executable that uses DLL side-loading with various injection techniques to execute malicious payloads. It abuses legitimate applications such as x64dbg.exe and MonitoringHost.exe to load malicious DLLs, which leads to subsequent stages and shellcode.

First seen
January 2025
Last seen
September 2026
Alert Name
Win64.Trojan.Sadbridge