ZeroFox Intelligence Flash Report - Innovative Loader-as-a-Service Announced
|by Alpha Team

ZeroFox Intelligence Flash Report - Innovative Loader-as-a-Service Announced
Product Serial: F-2024-02-07b
TLP:CLEAR
In this flash report, ZeroFox researchers report on a new malware loader-as-a-service offering gaining traction on the predominantly Russian-speaking dark web forum exploit[.]in. The currently unnamed loader allegedly targets Windows operating systems and is signed using valid certificates.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Since its announcement on January 25, 2024, by untested actor “Null14”, an innovative malware loader-as-a-service offering has been gaining traction on the predominantly Russian-speaking dark web community exploit[.]in.
- The currently unnamed loader allegedly targets Windows operating systems and is signed using valid certificates, enabling its deployment to remain undetected by various Windows systems as well as VirusTotal.
- Although ZeroFox can neither confirm nor disconfirm the credibility of the service, positive indicators add credence to the legitimacy of this loader service as an innovative malware-spreading technique.
- Malware distribution based on emulating credible software is likely on an upward trajectory, and this trend is expected to continue in the first half of 2024.
Tags: tlp:clear, threat actor, malware