Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 2 actors

TerraLoader

TerraLoader is a malware loader associated with the financially motivated Venom Spider / Golden Chickens malware-as-a-service ecosystem. It is described as an advanced loader used to deliver custom payloads and additional Golden Chickens malware, with reported support for fileless execution techniques and DLL sideloading. Reporting also states that VenomLNK can execute TerraLoader as a loader module responsible for deploying further Golden Chickens tooling, and that TerraLoader has been used to install the More_eggs backdoor. Code similarities have also been noted between TerraLoader and later JavaScript payloads used in Venom Spider intrusion chains.

TerraLoader has additionally been observed in Evilnum activity, where a component called TerraLoader was used to collect hardware and file information to detect sandboxed environments, indicating anti-analysis and virtualization/sandbox evasion functionality. Across the provided reporting, TerraLoader is consistently positioned as a mature, established Golden Chickens loader compared with newer families such as TerraStealerV2 and TerraLogger. Associated actors and users mentioned in the content include Venom Spider / Golden Chickens and Evilnum. High-confidence behaviors directly mentioned in the content include payload delivery, deployment of additional malware, fileless attack support, DLL sideloading, installation of More_eggs, and sandbox-environment checks based on hardware and file information.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
FIN6

Venom Spider, also known as GOLDEN CHICKENS, is a threat actor known for offering Malware-as-a-Service (MaaS) tools like VenomLNK, TerraLoader, TerraStealer, and TerraCryptor.

via zscaler threat labzzscaler.com
Cobalt Group

"B. TerraLoader Advanced malware loader designed to deliver custom payloads. Can execute fileless attacks... including DLL sideloading."

via cyberthronethecyberthrone.in
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059.007JavaScriptEvidence1
TacticExecution

The essence of this technique is to use a legitimate application – in this case, ie4uinit.exe – to execute commands and run JavaScript code.

Stealth

1 technique
T1497.001System ChecksEvidence1

Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments.

Discovery

1 technique
T1497.001System ChecksEvidence1

Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.