Threat reportMalwareTL-2026-2147
D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and Telegram/Pastebin Dead-Drop C2
D3F@ck Loader (TL-2026-2147), also tracked as D3F@CK Loader, is a high-severity malware campaign, first published 2026-08-25. It is attributed to Sergei Panteleevich (Russia) with medium confidence, affects Microsoft Windows (desktop and server, any version capable of running, maps to 15 MITRE ATT&CK techniques (T1027, T1057, T1059.001), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 1Sergei Panteleevich
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-2147
- Threat ID
- TL-2026-2147
- Also known as
- D3F@CK Loader
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Sergei Panteleevich
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- general opportunistic no sector-specific targeting evidenced in sources
- Target regions
- global — no region-specific victim targeting evidenced in sources
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in D3F@ck Loader
Malware and tooling: D3F@CK Loader, DanaBot, Latrodectus - S1160, Lumma Stealer - S1213, MetaStealer, Pronsis Loader, Raccoon Stealer - S1148, SectopRAT, Inno Setup, JPHP / DevelNext, Nullsoft Scriptable Install System (NSIS)
How D3F@ck Loader works
A JPHP-based Windows malware loader — statically decompiled by researcher Tony Lambert and independently profiled by eSentire's Threat Response Unit as the malware-as-a-service offering 'D3F@ck Loader' — ships as an Inno Setup installer that drops a PE executable with a bundled JRE and a ZIP/JAR overlay. It disables Windows Defender via a hidden, elevated PowerShell command, downloads and executes arbitrary second-stage payloads (Raccoon Stealer, MetaStealer, SectopRAT, DanaBot), and receives base64-encoded commands through Telegram channel page metadata and Pastebin dead-drops.
Tony Lambert's static decompilation analysis (binwalk + cfr, published 2024-07-20) examined a Windows PE binary with a ZIP archive appended as an overlay. The executable is designed to be run via a bundled JRE as `javaw.exe -jar <path>`, letting Java read the ZIP-from-end-of-file structure while a naive file-type scan sees only a native PE. Inside the ZIP is a JPHP (a Java implementation of PHP, distributed as 'DevelNext') application: compiled `.phb` bytecode, a `JPHP-INF/.bootstrap` entry pointing at an `app\modules\AppModule` module, and GUI 'MainForm' components. Lambert's decompiled code contains an `executePowerShellCommand`-style routine that spawns a hidden, elevated PowerShell process to run `Add-MpPreference -Force -ExclusionPath "C:\"`, excluding the entire system drive from Windows Defender scanning, then downloads and executes an arbitrary secondary payload (referenced in code as `93.exe`). Command and control is handled through two low-cost, hard-to-take-down channels: a Telegram channel whose public page `og:description` meta tag holds a base64-encoded instruction blob, and Pastebin pastes (since taken down) serving the same role as a dead-drop resolver. The sample carries the SHA-256 hash `94edf5396599aaa9fca9c1a6ca5d706c130ff1105f7bd1acff83aff8ad513164` and was catalogued on MalwareBazaar; Lambert notes the code is only lightly obfuscated beyond selective base64 encoding, consistent with a functionality-first MaaS product rather than a heavily evasion-hardened targeted tool.
eSentire's Threat Response Unit (first published April 2024) independently tracked the same family end-to-end as 'D3F@ck Loader,' a malware-as-a-service offering that begins distribution as an Inno Setup installer (Pascal scripting) bundling a 7-Zip tool, the `elevate.exe` UAC-bypass helper, a `Setup.exe` Java payload executor, and password-protected archives holding the JPHP dependencies — before handing off to the same JPHP/`dn-compiled-module.jar` stage Lambert decompiled. eSentire observed the loader check in with the C2 domain `jilinebyli[.]top` using status commands 'ready', 'starting', 'downloaded', and 'finished', and documented an active Telegram dead-drop channel (`t.me/+UfHrjVyCLZ03ODYy`) as a fallback resolver. Distribution leans on malvertising and trojanized/cracked-software downloads, with installers signed using purchased Extended Validation (EV) code-signing certificates (under front company names such as 'LLC Kama Lubricant Company', 'Ayog Tech Ltd', and 'MAD PANDA Ltd') specifically to suppress SmartScreen warnings. Over 2024 the operator iterated the loader's evasion: a custom base64 alphabet (April 2024), a 12-position Caesar cipher layer (May 2024), and anti-sandbox checks for `VboxService.exe`/`Vmwareuser.exe`/`Vmtoolsd.exe` plus a minimum-120GB disk-space gate (August 2024). Confirmed second-stage payloads include Raccoon Stealer, MetaStealer, SectopRAT, and DanaBot. eSentire assesses with medium confidence that the developer operates under the persona 'Sergei Panteleevich' (Telegram handles @Mavr_MMM/@AO_MMM/@GhostBustersKING, forum handle Null14), recruits for a distribution group called 'MMM Team'/'GhostBusters' that specifically pushes MetaStealer, and sells the EV certificates commercially (~$3,000/year with custom company-name options); they assess the individual is likely in his late 30s and once lived in Chelyabinsk, Russia.
Trustwave SpiderLabs (2024-10-08) subsequently documented a sibling family, 'Pronsis Loader,' that shares the same JPHP payload lineage — samples are noted as 'easily interchangeable' with D3F@ck Loader — but diverges at the stager: Pronsis uses NSIS instead of Inno Setup, hides its malicious code behind a benign-looking `FailWorker-Install.exe` installer, and triggers JPHP execution via an NSIS plugin (`Nact.dll`). Earliest Pronsis samples date to November 2023. Pronsis has been observed delivering Lumma Stealer and Latrodectus (the latter establishing persistence via a scheduled task that re-runs every 10 minutes, per secondary reporting on the Trustwave findings). Because JPHP compiles to a bytecode format (`.phb`, `CAFEBABE`-prefixed) that standard Java decompilers cannot render, both loader families rely on this niche runtime specifically to frustrate reverse engineering — the same property that made JPHP notable when IceRat first used it in 2020.
Operationally, this is a disposable-loader/MaaS threat: no CVE is involved, defenders should not expect the loader binary itself to be stable, and detection should focus on the durable behavioral chain (JRE abused to run a ZIP-overlay PE, PowerShell-driven Defender-exclusion tampering, and Telegram/Pastebin-page-scraping C2) rather than any single hash or C2 domain, which the operator has already shown a pattern of iterating.
MITRE ATT&CK techniques used in TL-2026-2147
Defense Evasion
T1027 Obfuscated Files or Information; T1497.001 System Checks
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.001 PowerShell; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1132.001 Standard Encoding; T1132.002 Non-Standard Encoding
Privilege Escalation
T1548.002 Bypass User Account Control
defense-impairment
T1553.002 Code Signing; T1685 Disable or Modify Tools
Resource Development
Affected products and versions in D3F@ck Loader
- Microsoft — Windows (desktop and server, any version capable of running a bundled JRE)
Vulnerable versions: Not version-specific — a malware loader rather than a software vulnerability; any Windows host on which a user executes the trojanized installer is at risk
Remediation for D3F@ck Loader
Patches
- No vendor patch applicable — this is a malware loader, not a software vulnerability; mitigation is behavioral and detection-based
Immediate actions
- Block/monitor outbound traffic to the known D3F@ck Loader C2 domain jilinebyli.top
- Alert on and block PowerShell invocations that add a Windows Defender exclusion for the entire C:\ drive (Add-MpPreference -Force -ExclusionPath) or that spawn hidden, elevated child PowerShell processes (-WindowStyle hidden -Verb RunAs)
- Hunt for javaw.exe processes launching -jar against executables located outside standard JRE/application install paths
- Block or flag execution of installers signed with newly-issued EV code-signing certificates originating from consumer software-cracking, keygen, or pirated-media distribution sites
Workarounds
- Restrict or audit third-party JRE/JDK installation on end-user endpoints where Java is not a business requirement
- Educate users on the risk of downloading cracked/pirated software and clicking malvertising links, the primary observed distribution vectors
Longer-term hardening
- Deploy application allowlisting / WDAC so bundled or portable JRE binaries (javaw.exe) cannot execute arbitrary appended archives
- Enable Windows Defender tamper protection so exclusions cannot be silently added, even from an elevated PowerShell context
- Monitor egress to Telegram (t.me) and Pastebin from endpoints with no legitimate business need, as a dead-drop-resolver C2 detection signal
- Maintain detections for the downstream payload families this loader delivers (Raccoon Stealer, MetaStealer, SectopRAT, DanaBot, Lumma Stealer, Latrodectus), since the loader binary itself is disposable and frequently re-obfuscated
Timeline of D3F@ck Loader
- Threat actor 'Sergei' (alias Mavr_MMM / Null14) begins recruiting for the 'MMM Team' distribution group via Russian-language hacking forums, per eSentire TRU's actor-attribution research.
- A Telegram account later tied to the D3F@ck Loader developer is created; it is subsequently repurposed as a Telegram-based dead-drop C2 channel.
- Earliest known samples of Pronsis Loader — a JPHP-based sibling loader that later diverges from D3F@ck Loader — are observed, per Trustwave SpiderLabs.
- Initial D3F@ck Loader payloads are distributed in the wild, delivering Raccoon Stealer, MetaStealer, SectopRAT, and DanaBot, per eSentire TRU.
- eSentire's Threat Response Unit publishes the first public analysis identifying D3F@ck Loader as a malware-as-a-service offering with EV-certificate-signed installers, attributing development to the alias 'Sergei Panteleevich.'
- The loader developer introduces a custom base64 alphabet to obfuscate C2 strings, per eSentire TRU's version tracking.
- A 12-position Caesar cipher obfuscation layer is added to the loader's C2 string handling, per eSentire TRU.
- Researcher Tony Lambert publishes a static decompilation analysis (binwalk + cfr) of a JPHP-based loader sample, documenting the PowerShell Windows Defender exclusion command, javaw.exe -jar execution method, and Telegram/Pastebin base64 C2, identifying it as suspected D3F@ck Loader.
- The loader is updated to add an anti-sandbox minimum-disk-space check (>=120GB) and changes to its build path artifacts, per eSentire TRU.
- Trustwave SpiderLabs publishes analysis of Pronsis Loader, a JPHP-driven loader sharing D3F@ck Loader's codebase lineage but using NSIS instead of Inno Setup, delivering Lumma Stealer and Latrodectus.
Sources cited for D3F@ck Loader
Detection coverage for TL-2026-2147
As of 2026-08-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2147 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.