Skip to content
Emerging Threat: Kiss Loader Malware Exploits Early Bird APC Injection

Emerging Threat: Kiss Loader Malware Exploits Early Bird APC Injection

First seen 26 Mar 2026, 09:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 27, 2026 at 09:16 UTC
  • Kiss Loader uses Early Bird APC injection to stealthily infiltrate Windows systems.
  • The malware was first detected in early March 2026 and is still under active development.
  • It employs a multi-stage execution flow, including dynamic payload delivery via WebDAV.

A new malware loader named 'Kiss Loader' has been identified, utilizing advanced process injection techniques, specifically Early Bird APC injection, to infiltrate Windows systems. The malware was first spotted in early March 2026 and is still under active development, indicating a potential for future evolution into a more sophisticated attack tool. The infection vector begins with a Windows Internet Shortcut file that connects to a remote WebDAV resource, allowing the attacker to dynamically host payloads. Kiss Loader employs a multi-stage execution flow, including a JScript component that orchestrates the infection process and establishes persistence on the victim's system. The loader is capable of deploying additional payloads, including a variant of VenomRAT. Security analysts are closely monitoring this emerging threat as it poses significant risks to users and organizations alike.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 168d ago How this analysis works

Timeline

2026-03-01
Kiss Loader first spotted in the wild
2026-03-24
Detailed analysis of Kiss Loader published
2026-03-26
Current status of Kiss Loader reported by multiple sources

More articles in this cluster (4)

Following this threat?

Track AsyncRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed