Spoofed GlobalProtect Used to DeliverUnique WikiLoader Variant
ID: e03c31ee-7acd-49ab-8cbc-b9f5f0055992
STIX ID: report--e03c31ee-7acd-49ab-8cbc-b9f5f0055992
Threat Score
70/100
Uploaded: 2026-04-30
Published Date: 2026-04-30
Last Modified Date: 2026-04-30
Created by: KG-research
TLP:CLEAR
...
...
## Executive Summary
Unit 42 describes an active WikiLoader (WailingCrab) campaign that used SEO poisoning and spoofed GlobalProtect download pages to deliver a multi-stage Windows loader. The campaign abuses renamed legitimate binaries and DLL sideloading, decrypts and injects shellcode into explorer.exe, leverages WordPress sites and MQTT brokers for C2, and employs multiple anti-analysis and evasion techniques; the report includes comprehensive technical analysis, IOCs (URLs and SHA-256 hashes), and XQL hunting queries for detection.
