GuLoader samples seen in MalwareBazaar

Report date September 11, 2026

GuLoader installs other malware. Removing its first file may leave the malware it already downloaded on the device.

Background

CrowdStrike's investigation documented email attachments delivering GuLoader, which then fetched malware including FormBook, Agent Tesla and NanoCore. Those were observed payloads in that investigation, not a promise that every GuLoader file installs the same thing.

What to do

If your antivirus reports GuLoader, open its detection history to see whether the threat was blocked, quarantined or still needs action. If you use Microsoft Defender on Windows, open Windows Security > Virus & threat protection > Protection history. If the status is Threat found - action needed, follow Defender's recommended action. Threat blocked means Defender reports it removed that threat. Keep a quarantined file quarantined; do not choose Allow on device.

If GuLoader ran, ask IT to check for additional malware it downloaded and launched. On a personal Windows device, run a full antivirus scan and follow the removal instructions for every detection. If a password stealer is found to have run, secure the affected accounts from a clean device. Deleting the original attachment alone is not sufficient.

Feed records

MalwareBazaar listed 1 file sample tagged GuLoader among the 100 uploads checked for this report. This is a count of feed entries, not infected devices. The background above was checked on 2026-09-08; the feed records have their own observation dates.