DodgeBox | ThreatLabz
ID: 4d188e4c-f34d-4765-98c8-1b2a7bc8dee7
STIX ID: report--4d188e4c-f34d-4765-98c8-1b2a7bc8dee7
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2024-07-25
Last Modified Date: 2024-07-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Zscaler ThreatLabz details the discovery and technical analysis of DodgeBox, a sophisticated reflective DLL loader used to deploy the MoonWalk backdoor; the report describes the attack chain (signed EXE DLL sideloading -> DodgeBox -> encrypted DAT -> MoonWalk using Google Drive C2), multiple advanced evasion techniques (stack spoofing, DLL hollowing/sideloading, CFG disabling, environment keying), telemetry linking samples to Southeast Asia, IOC listings, and attribution to APT41 with moderate confidence.
