Experts shared up-to-date C2 domains and other artifacts related to recent MintsLoader attacks
Security Affairs
MAY 5, 2025
If the target passes the checks, the loader downloads advanced malware like GhostWeaver, a PowerShell-based RAT with TLS-encrypted C2 communication and capabilities to redeploy MintsLoader. If the system fails validation, the C2 may deliver a decoy executable like AsyncRAT, which has led to misclassifications in threat reports.
Let's personalize your content