New Kiss Loader Malware Targets Systems With Early Bird APC Injection

A newly identified malware loader, dubbed Kiss Loader, has been discovered actively targeting Windows systems via a multi-stage infection chain culminating in the injection of the Early Bird APC process.

The discovery, reported by G DATA’s TechBlog, stands out not only for its technical sophistication but also for an extraordinary development during analysis: the researcher engaged in a direct, real-time conversation with the threat actor behind the malware.

Kiss Loader is a Python-based loader currently under active development. It was first identified on March 10, 2026, when researchers observed newly deployed files on an open WebDAV directory that lacked any access restrictions.

The malware employs a layered execution chain designed to evade detection, deliver remote access tools, and maintain persistence on compromised machines.

Its capabilities, combined with evidence of ongoing development, mark it as a potential emerging threat worth close monitoring.

Multi-Stage Infection Chain and Payload Delivery

The attack begins with a Windows Internet Shortcut file named DKM_DE000922.pdf.url, which connects to a remote WebDAV resource hosted through a TryCloudflare tunnel.

This Cloudflare service creates temporary public tunnels to locally hosted services without requiring dedicated infrastructure.

This setup allows the attacker to host and dynamically update payloads with minimal footprint.

The final execution stage is achieved by injecting the Early Bird APC into the legitimate Windows process explorer.exe.

The loader creates the target process in a suspended state, allocates executable memory, and writes decrypted shellcode into it.

Rather than creating a new thread, it queues an Asynchronous Procedure Call (APC) to the primary thread of the suspended process.

When the thread resumes, the APC executes before normal process execution begins, allowing the shellcode to run under the context of a trusted system process significantly enhancing stealth and bypassing many endpoint detection mechanisms.

According to G Data Software research, a response appeared. The threat actor confirmed remote access, discussed their development process, and acknowledged working on the malware in different forms while experimenting with various techniques.

When asked directly about the injection method, the actor confirmed it was “early bird injection” validating the technical findings in real time. The exchange was brief; the actor eventually stopped responding and did not reconnect.

The incident highlights a rare but important principle: analysis environments must remain fully isolated, as the boundary between analyst and adversary can become unexpectedly thin.

Kiss Loader’s infrastructure and codebase show clear signs of active development, including embedded testing utilities, verbose runtime output, and detailed inline comments describing decryption and injection logic indicators consistent with early-stage tooling or AI-assisted code generation.

Indicators Of Compromise (IoCs)

File NameSHA-256 Hash
DKM_DE000922.pdf.url6abd118a0e6f5d67bfe1a79dacc1fd198059d8d66381563678f4e27ecb413fa7
oa.wshe8f83d67a6b894399fad774ac196c71683de9ddca3cf0441bb95318f5136b553
ccv.js549c1f1998f22e06dde086f70f031dbf5a3481bd3c5370d7605006b6a20b5b0

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories