Emerging Threat: Kiss Loader Malware Exploits Early Bird APC Injection

Emerging Threat: Kiss Loader Malware Exploits Early Bird APC Injection

First seen 26 Mar 2026, 09:46 UTC Feeds.FeedburnerGbhackersCybersecuritynewsSocprime 79% similarity 63.5

Article Content

Browse articles
ThreatCluster

A new malware loader named 'Kiss Loader' has been identified, utilizing advanced process injection techniques, specifically Early Bird APC injection, to infiltrate Windows systems. The malware was first spotted in early March 2026 and is still under active development, indicating a potential for future evolution into a more sophisticated attack tool. The infection vector begins with a Windows Internet Shortcut file that connects to a remote WebDAV resource, allowing the attacker to dynamically host payloads. Kiss Loader employs a multi-stage execution flow, including a JScript component that orchestrates the infection process and establishes persistence on the victim's system. The loader is capable of deploying additional payloads, including a variant of VenomRAT. Security analysts are closely monitoring this emerging threat as it poses significant risks to users and organizations alike.

Key Points: • Kiss Loader uses Early Bird APC injection to stealthily infiltrate Windows systems. • The malware was first detected in early March 2026 and is still under active development. • It employs a multi-stage execution flow, including dynamic payload delivery via WebDAV.

ThreatCluster AI

Timeline

2026-03-01
Kiss Loader first spotted in the wild
2026-03-24
Detailed analysis of Kiss Loader published
2026-03-26
Current status of Kiss Loader reported by multiple sources

Community

Browse all →

Tracked Entities in This Story