logo

Spoofed GlobalProtect Used to DeliverUnique WikiLoader Variant

ID: e03c31ee-7acd-49ab-8cbc-b9f5f0055992

STIX ID: report--e03c31ee-7acd-49ab-8cbc-b9f5f0055992

Threat Score

70/100

Uploaded: 2026-04-30

Published Date: 2026-04-30

Last Modified Date: 2026-04-30

Created by: KG-research

TLP:CLEAR
...
...
## Executive Summary Unit 42 describes an active WikiLoader (WailingCrab) campaign that used SEO poisoning and spoofed GlobalProtect download pages to deliver a multi-stage Windows loader. The campaign abuses renamed legitimate binaries and DLL sideloading, decrypts and injects shellcode into explorer.exe, leverages WordPress sites and MQTT brokers for C2, and employs multiple anti-analysis and evasion techniques; the report includes comprehensive technical analysis, IOCs (URLs and SHA-256 hashes), and XQL hunting queries for detection.