DridexLoader malware family
DridexLoader is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-08-05, most recently 2026-08-23. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 9
- First seen: 2026-08-05
- Last seen: 2026-08-23
- Verdicts: malicious 9
- File types: pe 9
ATT&CK techniques used by DridexLoader
- T1112 - 1 sample
Extracted command-and-control infrastructure
- 167.86.83.205:443,217.61.57.191:8172,5.196.213.55:808 - 9 samples
Recent DridexLoader samples
- 1cea934537d9819848cfd329fdcd579ca7726ff9e5ae88393f03405eb2a4cb30 - malicious (2026-08-23)
- 114759ef54599da27101f07cc936b63ce21f074d067d63adf70a914d27aac079 - malicious (2026-08-23)
- b08c10362022ecc692b1cbf5064d3796701863e6e77b92cf8b4dd119b1642ebb - malicious (2026-08-23)
- 211209fa83fe13308eeb1fbbe3a968660dede6b2767085b8b79bde996a35b7dc - malicious (2026-08-23)
- 67e6d0143a8056a6e3c68453c11668e4c1b39d884583e4aa7b4670989d8acc15 - malicious (2026-08-20)
- 2849f9a7d8a4ce1076f7e6cbbae55dd34fb6fdf630dbe3f39323bcb6727d597e - malicious (2026-08-20)
- 695043beced5c849b3922211034c9b187e4724b7b6603a20c949b1f2f43d6c9f - malicious (2026-08-20)
- e03397bf9b96a9605fc4ba976cf3db90cb1b014dcf463857c9f05acd0293b60c - malicious (2026-08-19)
- 052dfa08c15dd217d9735f719ef127f063319abcbac0cbc17915edc6ff0c08d9 - malicious (2026-08-05)
Frequently asked about DridexLoader
- What is DridexLoader?
- DridexLoader is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-08-05, most recently 2026-08-23. Observed ATT&CK techniques include T1112.
- How many DridexLoader samples have been analyzed?
- MalwareAnalyzer by Cyble holds 9 publicly analyzed samples attributed to DridexLoader, first seen 2026-08-05 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does DridexLoader use?
- Across our DridexLoader samples the most frequently observed techniques are T1112 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does DridexLoader use?
- DridexLoader samples in this corpus are distributed as pe (9).
- Does DridexLoader use command-and-control infrastructure?
- Yes. 1 distinct command-and-control indicator has been extracted from DridexLoader samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is DridexLoader malicious?
- 9 of 9 analyzed DridexLoader samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends