Threat reportMalwareTL-2026-2147

D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and Telegram/Pastebin Dead-Drop C2

highACTIVE

D3F@ck Loader (TL-2026-2147), also tracked as D3F@CK Loader, is a high-severity malware campaign, first published 2026-08-25. It is attributed to Sergei Panteleevich (Russia) with medium confidence, affects Microsoft Windows (desktop and server, any version capable of running, maps to 15 MITRE ATT&CK techniques (T1027, T1057, T1059.001), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
1Sergei Panteleevich
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-2147

Threat ID
TL-2026-2147
Also known as
D3F@CK Loader
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Sergei Panteleevich
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
general opportunistic no sector-specific targeting evidenced in sources
Target regions
global — no region-specific victim targeting evidenced in sources
Detection rules
9
Indicators of compromise
22

Malware and tooling in D3F@ck Loader

Malware and tooling: D3F@CK Loader, DanaBot, Latrodectus - S1160, Lumma Stealer - S1213, MetaStealer, Pronsis Loader, Raccoon Stealer - S1148, SectopRAT, Inno Setup, JPHP / DevelNext, Nullsoft Scriptable Install System (NSIS)

How D3F@ck Loader works

A JPHP-based Windows malware loader — statically decompiled by researcher Tony Lambert and independently profiled by eSentire's Threat Response Unit as the malware-as-a-service offering 'D3F@ck Loader' — ships as an Inno Setup installer that drops a PE executable with a bundled JRE and a ZIP/JAR overlay. It disables Windows Defender via a hidden, elevated PowerShell command, downloads and executes arbitrary second-stage payloads (Raccoon Stealer, MetaStealer, SectopRAT, DanaBot), and receives base64-encoded commands through Telegram channel page metadata and Pastebin dead-drops.

Tony Lambert's static decompilation analysis (binwalk + cfr, published 2024-07-20) examined a Windows PE binary with a ZIP archive appended as an overlay. The executable is designed to be run via a bundled JRE as `javaw.exe -jar <path>`, letting Java read the ZIP-from-end-of-file structure while a naive file-type scan sees only a native PE. Inside the ZIP is a JPHP (a Java implementation of PHP, distributed as 'DevelNext') application: compiled `.phb` bytecode, a `JPHP-INF/.bootstrap` entry pointing at an `app\modules\AppModule` module, and GUI 'MainForm' components. Lambert's decompiled code contains an `executePowerShellCommand`-style routine that spawns a hidden, elevated PowerShell process to run `Add-MpPreference -Force -ExclusionPath "C:\"`, excluding the entire system drive from Windows Defender scanning, then downloads and executes an arbitrary secondary payload (referenced in code as `93.exe`). Command and control is handled through two low-cost, hard-to-take-down channels: a Telegram channel whose public page `og:description` meta tag holds a base64-encoded instruction blob, and Pastebin pastes (since taken down) serving the same role as a dead-drop resolver. The sample carries the SHA-256 hash `94edf5396599aaa9fca9c1a6ca5d706c130ff1105f7bd1acff83aff8ad513164` and was catalogued on MalwareBazaar; Lambert notes the code is only lightly obfuscated beyond selective base64 encoding, consistent with a functionality-first MaaS product rather than a heavily evasion-hardened targeted tool.

eSentire's Threat Response Unit (first published April 2024) independently tracked the same family end-to-end as 'D3F@ck Loader,' a malware-as-a-service offering that begins distribution as an Inno Setup installer (Pascal scripting) bundling a 7-Zip tool, the `elevate.exe` UAC-bypass helper, a `Setup.exe` Java payload executor, and password-protected archives holding the JPHP dependencies — before handing off to the same JPHP/`dn-compiled-module.jar` stage Lambert decompiled. eSentire observed the loader check in with the C2 domain `jilinebyli[.]top` using status commands 'ready', 'starting', 'downloaded', and 'finished', and documented an active Telegram dead-drop channel (`t.me/+UfHrjVyCLZ03ODYy`) as a fallback resolver. Distribution leans on malvertising and trojanized/cracked-software downloads, with installers signed using purchased Extended Validation (EV) code-signing certificates (under front company names such as 'LLC Kama Lubricant Company', 'Ayog Tech Ltd', and 'MAD PANDA Ltd') specifically to suppress SmartScreen warnings. Over 2024 the operator iterated the loader's evasion: a custom base64 alphabet (April 2024), a 12-position Caesar cipher layer (May 2024), and anti-sandbox checks for `VboxService.exe`/`Vmwareuser.exe`/`Vmtoolsd.exe` plus a minimum-120GB disk-space gate (August 2024). Confirmed second-stage payloads include Raccoon Stealer, MetaStealer, SectopRAT, and DanaBot. eSentire assesses with medium confidence that the developer operates under the persona 'Sergei Panteleevich' (Telegram handles @Mavr_MMM/@AO_MMM/@GhostBustersKING, forum handle Null14), recruits for a distribution group called 'MMM Team'/'GhostBusters' that specifically pushes MetaStealer, and sells the EV certificates commercially (~$3,000/year with custom company-name options); they assess the individual is likely in his late 30s and once lived in Chelyabinsk, Russia.

Trustwave SpiderLabs (2024-10-08) subsequently documented a sibling family, 'Pronsis Loader,' that shares the same JPHP payload lineage — samples are noted as 'easily interchangeable' with D3F@ck Loader — but diverges at the stager: Pronsis uses NSIS instead of Inno Setup, hides its malicious code behind a benign-looking `FailWorker-Install.exe` installer, and triggers JPHP execution via an NSIS plugin (`Nact.dll`). Earliest Pronsis samples date to November 2023. Pronsis has been observed delivering Lumma Stealer and Latrodectus (the latter establishing persistence via a scheduled task that re-runs every 10 minutes, per secondary reporting on the Trustwave findings). Because JPHP compiles to a bytecode format (`.phb`, `CAFEBABE`-prefixed) that standard Java decompilers cannot render, both loader families rely on this niche runtime specifically to frustrate reverse engineering — the same property that made JPHP notable when IceRat first used it in 2020.

Operationally, this is a disposable-loader/MaaS threat: no CVE is involved, defenders should not expect the loader binary itself to be stable, and detection should focus on the durable behavioral chain (JRE abused to run a ZIP-overlay PE, PowerShell-driven Defender-exclusion tampering, and Telegram/Pastebin-page-scraping C2) rather than any single hash or C2 domain, which the operator has already shown a pattern of iterating.

MITRE ATT&CK techniques used in TL-2026-2147

Defense Evasion

T1027 Obfuscated Files or Information; T1497.001 System Checks

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.001 PowerShell; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1132.001 Standard Encoding; T1132.002 Non-Standard Encoding

Privilege Escalation

T1548.002 Bypass User Account Control

defense-impairment

T1553.002 Code Signing; T1685 Disable or Modify Tools

Resource Development

T1583.001 Domains; T1588.003 Code Signing Certificates

Affected products and versions in D3F@ck Loader

  • Microsoft — Windows (desktop and server, any version capable of running a bundled JRE)
    Vulnerable versions: Not version-specific — a malware loader rather than a software vulnerability; any Windows host on which a user executes the trojanized installer is at risk

Remediation for D3F@ck Loader

Patches

  • No vendor patch applicable — this is a malware loader, not a software vulnerability; mitigation is behavioral and detection-based

Immediate actions

  • Block/monitor outbound traffic to the known D3F@ck Loader C2 domain jilinebyli.top
  • Alert on and block PowerShell invocations that add a Windows Defender exclusion for the entire C:\ drive (Add-MpPreference -Force -ExclusionPath) or that spawn hidden, elevated child PowerShell processes (-WindowStyle hidden -Verb RunAs)
  • Hunt for javaw.exe processes launching -jar against executables located outside standard JRE/application install paths
  • Block or flag execution of installers signed with newly-issued EV code-signing certificates originating from consumer software-cracking, keygen, or pirated-media distribution sites

Workarounds

  • Restrict or audit third-party JRE/JDK installation on end-user endpoints where Java is not a business requirement
  • Educate users on the risk of downloading cracked/pirated software and clicking malvertising links, the primary observed distribution vectors

Longer-term hardening

  • Deploy application allowlisting / WDAC so bundled or portable JRE binaries (javaw.exe) cannot execute arbitrary appended archives
  • Enable Windows Defender tamper protection so exclusions cannot be silently added, even from an elevated PowerShell context
  • Monitor egress to Telegram (t.me) and Pastebin from endpoints with no legitimate business need, as a dead-drop-resolver C2 detection signal
  • Maintain detections for the downstream payload families this loader delivers (Raccoon Stealer, MetaStealer, SectopRAT, DanaBot, Lumma Stealer, Latrodectus), since the loader binary itself is disposable and frequently re-obfuscated

Timeline of D3F@ck Loader

  • Threat actor 'Sergei' (alias Mavr_MMM / Null14) begins recruiting for the 'MMM Team' distribution group via Russian-language hacking forums, per eSentire TRU's actor-attribution research.
  • A Telegram account later tied to the D3F@ck Loader developer is created; it is subsequently repurposed as a Telegram-based dead-drop C2 channel.
  • Earliest known samples of Pronsis Loader — a JPHP-based sibling loader that later diverges from D3F@ck Loader — are observed, per Trustwave SpiderLabs.
  • Initial D3F@ck Loader payloads are distributed in the wild, delivering Raccoon Stealer, MetaStealer, SectopRAT, and DanaBot, per eSentire TRU.
  • eSentire's Threat Response Unit publishes the first public analysis identifying D3F@ck Loader as a malware-as-a-service offering with EV-certificate-signed installers, attributing development to the alias 'Sergei Panteleevich.'
  • The loader developer introduces a custom base64 alphabet to obfuscate C2 strings, per eSentire TRU's version tracking.
  • A 12-position Caesar cipher obfuscation layer is added to the loader's C2 string handling, per eSentire TRU.
  • Researcher Tony Lambert publishes a static decompilation analysis (binwalk + cfr) of a JPHP-based loader sample, documenting the PowerShell Windows Defender exclusion command, javaw.exe -jar execution method, and Telegram/Pastebin base64 C2, identifying it as suspected D3F@ck Loader.
  • The loader is updated to add an anti-sandbox minimum-disk-space check (>=120GB) and changes to its build path artifacts, per eSentire TRU.
  • Trustwave SpiderLabs publishes analysis of Pronsis Loader, a JPHP-driven loader sharing D3F@ck Loader's codebase lineage but using NSIS instead of Inno Setup, delivering Lumma Stealer and Latrodectus.

Sources cited for D3F@ck Loader

Detection coverage for TL-2026-2147

As of 2026-08-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2147 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats