Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

OffLoader

OffLoader is a loader/dropper malware family observed in multiple 2025-2026 distribution ecosystems, most notably as a payload in the Amadey botnet’s fbf543 pay-per-install campaign. It has been delivered as large Inno Setup installers compiled with Embarcadero Delphi/Borland, often carrying fake publisher metadata and substantial encrypted overlay data. Reported samples masqueraded as legitimate installers, including spoofed Microsoft Corporation version information and trojanized software packages such as a 7-Zip 16.02 installer. In the Amadey-linked activity, OffLoader was downloaded from 158.94.211.222 via paths such as /files/7782139129/4Qrxrgo.exe, with backend infrastructure tied to labinstalls.info on OMEGATECH hosting and Cloudflare-proxied C2 domains registered through Namecheap using two-word cheap-TLD naming patterns. Observed network paths included /connector for bot check-in, /config for campaign status, and /api/ for payload delivery.

Behavior attributed to OffLoader and its wrappers includes geofencing checks, debug-environment detection, process enumeration, execution delay via timeout.exe, and secondary payload delivery. One documented payload chain served a trojanized 7-Zip installer that requested administrator privileges, adjusted SeShutdownPrivilege, and established persistence by hijacking the legitimate 7-Zip shell extension CLSID {23170F69-40C1-278A-1000-000100020000}, registering DragDropHandlers and ContextMenuHandlers so code would execute on Windows Explorer right-click events. OffLoader has also been described as a secondary dropper delivering sunwukongs.exe in an ACRStealer-related ecosystem, and as an Inno Setup dropper delivering Vidar in a GALEON-AS cluster. Across reporting, OffLoader appeared alongside or delivered other malware families including Vidar, QuasarRAT, SalatStealer, Mirai, GCleaner, Fuery, and Amadey itself, indicating use as part of broader criminal distribution services rather than a single exclusive campaign.

High-confidence indicators mentioned in the content include the import hash ac4ded70f85ef621e5f8917b250855be linking an OffLoader sample to a Gh0stRAT fake-installer sample; an OffLoader sample SHA-256 of 2862dbcdc9546ab145d444a68b8112ce79487a93bdb7c4b45dc6649b640516ce; the Amadey delivery URL 158.94.211.222/files/7782139129/4Qrxrgo.exe; and the trojanized 7-Zip payload SHA-256 629ce3c424bd884e74aed6b7d87d8f0d75274fb87143b8d6360c5eec41d5f865. The malware has been associated with financially motivated cybercrime distribution infrastructure, including Amadey PPI operations and related multi-family malware hosting environments.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

13 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

MITRE ATT&CK Mapping ... Initial Access Phishing T1566 ClickFix/FakeCAPTCHA social engineering

T1566.002Spearphishing LinkEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Initial Access Phishing: Spearphishing Link T1566.002 Cracked software download links

Execution

1 technique
T1204.002Malicious FileEvidence2

EXECUTION (T1204.002) User executes IDM installer → Inno Setup dropper (OffLoader) OR Golang loader (Birkenhead)

Persistence

2 techniques
T1112Modify RegistryEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Persistence Modify Registry T1112 Shell extension registration in HKLM

T1546.015Component Object Model HijackingEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Persistence Event Triggered Execution: COM Hijacking T1546.015 CLSID shell extension hijack

Privilege Escalation

3 techniques
T1134Access Token ManipulationEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Privilege Escalation Access Token Manipulation T1134 SeShutdownPrivilege, CreateProcessWithToken

T1546.015Component Object Model HijackingEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Persistence Event Triggered Execution: COM Hijacking T1546.015 CLSID shell extension hijack

T1548.002Bypass User Account ControlEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Privilege Escalation Abuse Elevation Control T1548.002 requireAdministrator manifest

Stealth

4 techniques
T1027.002Software PackingEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Defense Evasion Obfuscated Files: Software Packing T1027.002 Encrypted Inno Setup payload, UPX

T1036.005Match Legitimate Resource Name or LocationEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Defense Evasion Masquerading: Match Legitimate Name T1036.005 7-Zip 16.02 installer disguise

T1134Access Token ManipulationEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Privilege Escalation Access Token Manipulation T1134 SeShutdownPrivilege, CreateProcessWithToken

T1497Virtualization/Sandbox EvasionEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Defense Evasion Virtualization/Sandbox Evasion T1497 Debug detection, geofencing

Defense Impairment

1 technique
T1112Modify RegistryEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Persistence Modify Registry T1112 Shell extension registration in HKLM

Discovery

2 techniques
T1497Virtualization/Sandbox EvasionEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Defense Evasion Virtualization/Sandbox Evasion T1497 Debug detection, geofencing

T1614System Location DiscoveryEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Discovery System Location Discovery T1614 Computer location settings check

Command and Control

2 techniques
T1090.003Multi-hop ProxyEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Command and Control Proxy: Multi-hop Proxy T1090.003 Cloudflare CDN proxying C2 traffic

T1105Ingress Tool TransferEvidence1

MITRE ATT&CK Mapping Tactic Technique ID Implementation Command and Control Ingress Tool Transfer T1105 Downloads setup.exe from /api/

INDICATORS OF COMPROMISE

IOCs tracked for this family

29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
22 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
6 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

breakglass intelNews
Mar 12, 2026
OffLoader: 100 C2 Domains, a Trojanized 7-Zip Installer, and the Amadey Botnet's Pay-Per-Install Machine - Breakglass Intelligence - Breakglass Intelligence

OffLoader is a loader/dropper distributed via the Amadey fbf543 pay-per-install campaign. It uses a weaponized Inno Setup wrapper with encrypted payload sections, performs geofencing and debug-environment checks, checks in to C2 endpoints such as /connector and /config, and retrieves a payload from /api/, including a trojanized 7-Zip installer that establishes persistence through shell extension hijacking.

Read more
breakglass intelNews
Mar 12, 2026
Gh0stRAT Returns as "openclawAI": A Chinese Cybercrime Operation Riding the AI Hype Train - Breakglass Intelligence - Breakglass Intelligence

Loader malware linked by shared imphash, compiler, and Inno Setup framework to the Gh0stRAT sample. The content says this OffLoader variant was distributed through the Amadey botnet, suggesting shared tooling or a commercial builder ecosystem.

Read more
breakglass intelNews
Mar 12, 2026
Amadey v5.x "fbf543" Campaign: A Pay-Per-Install Supermarket Running 24 Malware Families on Bulletproof Rails - Breakglass Intelligence - Breakglass Intelligence

OffLoader is a loader family included among the payloads distributed by the Amadey PPI service.

Read more
breakglass intelNews
Mar 8, 2026
ACRStealer Dissected: Decrypted Kill Chain, Stolen ASUS EV Certificate, and 9 Live C2 Servers Operating a Multi-Family Stealer Network - Breakglass Intelligence - Breakglass Intelligence

Secondary dropper/loader used in the ACRStealer distribution ecosystem to deliver the signed binary sunwukongs.exe.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching29

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping13

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.