#GeniexLoader

Malware/Tool

2026-05-21 • 2026년 4월 국내외 금융권 관련 보안 이슈

GeniexLoader is malware linked to BlueNoroff, also known as CryptoCore or APT38, and observed as the final installed payload after exploitation of WGear enterprise-banking software. The incident affected WGear versions through 1.100.7.0205, where remote code execution allowed the WGear process to launch mshta, retrieve external HTML, and execute staged payloads before installing GeniexLoader. Although Andariel had repeatedly exploited the same WGear vulnerability, the loader deployed in this operation was associated with BlueNoroff, demonstrating shared exploitation opportunities across DPRK-linked clusters.

Tagged Reports

« Back