GuLoader samples seen in MalwareBazaar
GuLoader installs other malware. Removing its first file may leave the malware it already downloaded on the device.
Background
CrowdStrike's investigation documented email attachments delivering GuLoader, which then fetched malware including FormBook, Agent Tesla and NanoCore. Those were observed payloads in that investigation, not a promise that every GuLoader file installs the same thing.
What to do
If your antivirus reports GuLoader, open its detection history to see whether the threat was blocked, quarantined or still needs action. If you use Microsoft Defender on Windows, open Windows Security > Virus & threat protection > Protection history. If the status is Threat found - action needed, follow Defender's recommended action. Threat blocked means Defender reports it removed that threat. Keep a quarantined file quarantined; do not choose Allow on device.
If GuLoader ran, ask IT to check for additional malware it downloaded and launched. On a personal Windows device, run a full antivirus scan and follow the removal instructions for every detection. If a password stealer is found to have run, secure the affected accounts from a clean device. Deleting the original attachment alone is not sufficient.
Feed records
MalwareBazaar listed 1 file sample tagged GuLoader among the 100 uploads checked for this report. This is a count of feed entries, not infected devices. The background above was checked on 2026-09-08; the feed records have their own observation dates.