GuLoader Exploits Polymorphic Code and Cloud Hosting for Malware Delivery

GuLoader Exploits Polymorphic Code and Cloud Hosting for Malware Delivery

First seen 10 Feb 2026, 16:42 UTC GbhackersCybersecuritynews 82% similarity 32.9

Article Content

Browse articles
ThreatCluster

GuLoader, also known as CloudEyE, has become a persistent threat in cybersecurity, functioning primarily as a downloader for secondary malware payloads. It retrieves and executes various malicious software, including the Remcos Remote Access Trojan and information stealers like Vidar and Raccoon Stealer, utilizing polymorphic code and trusted cloud infrastructure to evade detection.

ThreatCluster AI How this analysis works

Timeline

2026-02-10
GuLoader identified as a persistent threat
2026-02-10
GuLoader's capabilities detailed in cybersecurity articles

Community

Browse all →

Tracked Entities in This Story