# D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and Telegram/Pastebin Dead-Drop C2

> A JPHP-based Windows malware loader — statically decompiled by researcher Tony Lambert and independently profiled by eSentire's Threat Response Unit as the malware-as-a-service offering 'D3F@ck Loader' — ships as an Inno Setup installer that drops a PE executable with a bundled JRE and a ZIP/JAR overlay. It disables Windows Defender via a hidden, elevated PowerShell command, downloads and executes arbitrary second-stage payloads (Raccoon Stealer, MetaStealer, SectopRAT, DanaBot), and receives base64-encoded commands through Telegram channel page metadata and Pastebin dead-drops.

- **Published:** 2026-08-25T00:00:00Z
- **Last reviewed:** 2026-08-25T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2147
- **ID:** TL-2026-2147
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Sergei Panteleevich (Russia)
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Tony Lambert's static decompilation analysis (binwalk + cfr, published 2024-07-20) examined a Windows PE binary with a ZIP archive appended as an overlay. The executable is designed to be run via a bundled JRE as `javaw.exe -jar <path>`, letting Java read the ZIP-from-end-of-file structure while a naive file-type scan sees only a native PE. Inside the ZIP is a JPHP (a Java implementation of PHP, distributed as 'DevelNext') application: compiled `.phb` bytecode, a `JPHP-INF/.bootstrap` entry pointing at an `app\modules\AppModule` module, and GUI 'MainForm' components. Lambert's decompiled code contains an `executePowerShellCommand`-style routine that spawns a hidden, elevated PowerShell process to run `Add-MpPreference -Force -ExclusionPath "C:\"`, excluding the entire system drive from Windows Defender scanning, then downloads and executes an arbitrary secondary payload (referenced in code as `93.exe`). Command and control is handled through two low-cost, hard-to-take-down channels: a Telegram channel whose public page `og:description` meta tag holds a base64-encoded instruction blob, and Pastebin pastes (since taken down) serving the same role as a dead-drop resolver. The sample carries the SHA-256 hash `94edf5396599aaa9fca9c1a6ca5d706c130ff1105f7bd1acff83aff8ad513164` and was catalogued on MalwareBazaar; Lambert notes the code is only lightly obfuscated beyond selective base64 encoding, consistent with a functionality-first MaaS product rather than a heavily evasion-hardened targeted tool.

eSentire's Threat Response Unit (first published April 2024) independently tracked the same family end-to-end as 'D3F@ck Loader,' a malware-as-a-service offering that begins distribution as an Inno Setup installer (Pascal scripting) bundling a 7-Zip tool, the `elevate.exe` UAC-bypass helper, a `Setup.exe` Java payload executor, and password-protected archives holding the JPHP dependencies — before handing off to the same JPHP/`dn-compiled-module.jar` stage Lambert decompiled. eSentire observed the loader check in with the C2 domain `jilinebyli[.]top` using status commands 'ready', 'starting', 'downloaded', and 'finished', and documented an active Telegram dead-drop channel (`t.me/+UfHrjVyCLZ03ODYy`) as a fallback resolver. Distribution leans on malvertising and trojanized/cracked-software downloads, with installers signed using purchased Extended Validation (EV) code-signing certificates (under front company names such as 'LLC Kama Lubricant Company', 'Ayog Tech Ltd', and 'MAD PANDA Ltd') specifically to suppress SmartScreen warnings. Over 2024 the operator iterated the loader's evasion: a custom base64 alphabet (April 2024), a 12-position Caesar cipher layer (May 2024), and anti-sandbox checks for `VboxService.exe`/`Vmwareuser.exe`/`Vmtoolsd.exe` plus a minimum-120GB disk-space gate (August 2024). Confirmed second-stage payloads include Raccoon Stealer, MetaStealer, SectopRAT, and DanaBot. eSentire assesses with medium confidence that the developer operates under the persona 'Sergei Panteleevich' (Telegram handles @Mavr_MMM/@AO_MMM/@GhostBustersKING, forum handle Null14), recruits for a distribution group called 'MMM Team'/'GhostBusters' that specifically pushes MetaStealer, and sells the EV certificates commercially (~$3,000/year with custom company-name options); they assess the individual is likely in his late 30s and once lived in Chelyabinsk, Russia.

Trustwave SpiderLabs (2024-10-08) subsequently documented a sibling family, 'Pronsis Loader,' that shares the same JPHP payload lineage — samples are noted as 'easily interchangeable' with D3F@ck Loader — but diverges at the stager: Pronsis uses NSIS instead of Inno Setup, hides its malicious code behind a benign-looking `FailWorker-Install.exe` installer, and triggers JPHP execution via an NSIS plugin (`Nact.dll`). Earliest Pronsis samples date to November 2023. Pronsis has been observed delivering Lumma Stealer and Latrodectus (the latter establishing persistence via a scheduled task that re-runs every 10 minutes, per secondary reporting on the Trustwave findings). Because JPHP compiles to a bytecode format (`.phb`, `CAFEBABE`-prefixed) that standard Java decompilers cannot render, both loader families rely on this niche runtime specifically to frustrate reverse engineering — the same property that made JPHP notable when IceRat first used it in 2020.

Operationally, this is a disposable-loader/MaaS threat: no CVE is involved, defenders should not expect the loader binary itself to be stable, and detection should focus on the durable behavioral chain (JRE abused to run a ZIP-overlay PE, PowerShell-driven Defender-exclusion tampering, and Telegram/Pastebin-page-scraping C2) rather than any single hash or C2 domain, which the operator has already shown a pattern of iterating.

## MITRE ATT&CK

- T1204.002 Malicious File
- T1059.001 PowerShell
- T1548.002 Bypass User Account Control
- T1685 Disable or Modify Tools
- T1027 Obfuscated Files or Information
- T1553.002 Code Signing
- T1497.001 System Checks
- T1057 Process Discovery
- T1082 System Information Discovery
- T1102.001 Dead Drop Resolver
- T1071.001 Web Protocols
- T1132.001 Standard Encoding
- T1132.002 Non-Standard Encoding
- T1588.003 Code Signing Certificates
- T1583.001 Domains

## Sources

- [Decompiling a JPHP Loader with binwalk and cfr](https://forensicitguy.github.io/decompiling-jphp-loader-binwalk-cfr/)
- [Exploring the D3F@ck Malware-as-a-Service Loader](https://www.esentire.com/blog/exploring-the-d3f-ck-malware-as-a-service-loader)
- [Pronsis Loader: A JPHP-Driven Malware Diverging from D3F@ck Loader](https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pronsis-loader-a-jphp-driven-malware-diverging-from-d3fck-loader/)
- [Pronsis Loader (jar.pronsis_loader)](https://malpedia.caad.fkie.fraunhofer.de/details/jar.pronsis_loader)
- [Pronsis Loader: The Emerging Threat Behind JPHP-Driven Malware](https://securityonline.info/pronsis-loader-the-emerging-threat-behind-jphp-driven-malware/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2147
