Recorded campaigns
This loader has been observed in multiple campaigns.
The underground business scenario
An advertisement was found for the Buer loader in an underground forum on August 16.
Features
According to the description in the advertisement, this loader has a number of features.
Technical release notes for a version of this loader was also discovered in the underground forum post.
This malware is growing to be competitive in the underground markets, with the authors including features and adding updates. Researchers from Proofpoint who tracked this loader have provided the list of IOCs that you can refer to.
Publisher