Malware

New UULoader Attacking Users Via Weaponized PDF Documents

Malicious .msi installers disguised as legitimate software actively target Korean and Chinese speakers by dubbing UULoader, contain a loader likely developed by a Chinese speaker, and evade detection by most security solutions. 

The malware employs DLL side-loading to execute obfuscated payloads, potentially delivering remote access trojans or credential stealers

UULoader .pdb path.

UULoader primarily evades static detection by stripping file headers from its core components, which are typically the initial bytes of a file, and identifying file types for applications and the operating system.

Free Webinar on Detecting & Blocking Supply Chain Attack -> Book your Spot 

By removing these identifiers, UULoader’s executables, stored within a .cab archive, become unrecognizable to static analysis tools, hindering classification and detection and allowing the malware to masquerade as harmless data, evading scrutiny until execution. 

It employs a layered obfuscation technique by packaging a stripped, legitimate Realtek executable as a side-loader for another stripped DLL. 

A heavily obfuscated payload, destined for “XamlHost.sys,” resides in the .cab file alongside two tiny files containing “M” and “Z” characters, which are employed to repair the stripped headers of the aforementioned executable and DLL during UULoader’s execution, evading detection mechanisms. 

“M” and “Z” for header fix

Certain UULoader samples employ a deception tactic by including a legitimate decoy file alongside malicious components, which often mirror the .msi file’s purported function and aim to divert user attention from harmful activities. 

For instance, a “Chrome update” disguise might contain an authentic Chrome updater to mask malicious operations, while UULoader leverages an .msi CustomAction to establish a “Microsoft Thunder” directory in C:\Program Files (x86)\. 

Subsequently, it extracts and renames files from an embedded .cab, including a re-headered executable and DLL, and deploys an obfuscated final payload.

Concurrently, a .vbs script executes, excluding the newly created directory from Windows Defender protection. 

The script further processes extracted files and launches a legitimate “side loader” to invoke the UULoader DLL, which in turn loads the obfuscated payload and initiates a decoy application. 

Directory creation by .msi CustomAction.

The .vbs script employs obfuscation techniques by incorporating irrelevant arithmetic calculations to obscure malicious code within a seemingly legitimate script.

To further evade detection, the script excludes itself from Defender scans. It ultimately deploys and executes UULoader, a tool designed to deliver payloads like Gh0stRat and Mimikatz, indicating a potential threat of remote access and credential theft from actors possibly of Chinese origin. 

UULoader utilizes a complex, multi-phase payload delivery mechanism that effectively circumvents static detection tools, which is evidenced by its exceptionally low initial detection rates on VirusTotal. 

According to Cyberint, although it has not been determined who exactly is responsible for UULoader, the characteristics of the malware point to a possible origin in China.

Are you from SOC and DFIR Teams? Analyse Malware Incidents & get live Access with ANY.RUN -> Get 14 Days Free Acces

Cyber Advisory

CISO Advisory is a Team of Security Experts Covering Various Cybersecurity Research and Technical Write-ups.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago