216.73.217.22

Technical Analysis of GuLoader Obfuscation Techniques

· Published 09/02/2026 19:07 · Modified 09/02/2026 20:42

Export JSON

Essential information

Published
09/02/2026 19:07
Modified
09/02/2026 20:42
Tags
2026-02-09 anti-analysis cloudeye downloader exception-handling guloader obfuscation payload-decryption polymorphic-code string encryption
Related entities
6 observables, 14 techniques (mitre), 2 malware

Description

, a malware active since 2019, primarily delivers RATs and information stealers. It employs sophisticated techniques, including polymorphic code for dynamic constant construction and complex exception-based control flow . The malware has evolved to handle multiple exception types, making tracing its execution flow challenging. uses dynamic hashing, encrypted strings, and stack-based to conceal critical information. It often hosts payloads on trusted cloud services to bypass reputation-based detection. The malware's consistent development and updating of techniques suggest it will remain a significant threat in the future.

External references