MemLoader is a backdoor malware family referenced in reporting on a Mysterious Elephant APT cyber-espionage campaign targeting South Asian diplomacy. The available content identifies it as a new backdoor used in an operation associated with WhatsApp data theft. MemLoader is also mentioned as one of the custom-made or customized tools used alongside BabShell by Mysterious Elephant. Additional observed context shows files named MemLoader.dll appearing in malware delivery chains, including cases involving HWP decoy files and installer-themed executables such as nos-setup.exe and astx-setup.exe, with one cited sample MD5 of bea602695d58cbf25fff058834e36c1d. High-confidence details beyond these points, including its internal functionality, persistence, command-and-control protocol, or specific infection mechanism, are not available in the provided content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dropped malware MD5 ... bea602695d58cbf25fff058834e36c1d | MemLoader.dll ... Malware using hwp decoy file ... MemLoader.dll (png) ... MemLoader.dll (hwp).
Mysterious Elephant APT Campaign Targets South Asian Diplomacy, Steals WhatsApp Data with New MemLoader Backdoor
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader/downloader family referenced in related spoofing-page and decoy-document delivery chains. It appears as an intermediate payload used to load or deliver later-stage malware.
A loader delivered via fake security software installers (nos-setup.exe and astx-setup.exe). It is written to ProgramData as a .dat file and is used as an additional malicious payload in the broader campaign.
A newly referenced backdoor used in a cyber-espionage campaign targeting South Asian diplomacy and stealing WhatsApp data.
Customized loader module used by the Mysterious Elephant APT in recent campaigns (exact functionality not detailed in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.