FILEMembers
FILE

GuLoader Hits EU Healthcare via Danish Temp Folder and Forged 2013 Timestamp

A Polish-language NSIS dropper posing as a procurement order stages 15 payloads — including JPEG-embedded shellcode carriers — into a Danish-named temp directory before beaconing to cPanel-hosted C2 nodes in Germany and Serbia. The campaign targets healthcare organisations in Poland and Croatia with a layered anti-forensic stack that achieves a 15/16 sandbox evasion rate.

Jun 17, 2026, 10:36 (UTC+9)Last seenJun 17, 2026Severity100ByCTX TeamIOC21MITRE19RegionsHRPL

A 673-kilobyte Windows executable with a Polish-language filename — Zamowienie_829522.bat, meaning "Order 829522" — is the entry point for one of the more technically deliberate GuLoader campaigns CTX Team has tracked against European healthcare targets. The file is a Nullsoft Installer self-extracting archive, flagged by 49 of 77 antivirus engines under the label trojan.makoob/nsis, and it arrives carrying a PE timestamp set to Christmas Day 2013 — a date approximately eleven years before the…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence