
Godzilla Loader Campaign Byte-Mutates Five Variants, Exfiltrates India Victim's Documents
Five near-identical 9-kilobyte loaders with per-deployment byte mutations beacon to a shared PHP gate across three .ru domains. A FileGrabber module has already harvested a confirmed India-region victim's Documents folder twice, packaging the output with a unique victim token and dual July–August 2024 timestamps.
Five nearly identical 9-kilobyte Windows executables are circulating as the primary delivery mechanism for a Godzilla Loader campaign whose most operationally revealing detail is not the malware itself — it is the five zero-detection text files sitting in the same dataset, each one a harvested document from a victim's own machine, packaged with a unique victim token and dual collection timestamps from July and August 2024.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read