Home
Glossary
FakeBat
Table of contents
5 min
H2 title on one or more lines.
Share
Updated on
June 22, 2026

FakeBat malware

FakeBat is a loader malware that was rented to other cybercriminals as a subscription service. It is also tracked as EugenLoader, PaykLoader, and NUMOZYLOD. A loader has one job: get onto a machine and install the malware that carries out the theft, surveillance, fraud, or ransomware deployment. FakeBat was among the most widely distributed loaders of early 2024. Its operators sold access through an administration panel, build templates that made the loader look like legitimate software, and an optional distribution service that handled landing pages and delivery for customers. Its most effective campaigns used paid search ads, poisoned search results, fake browser updates, and imitation download pages for popular workplace applications. FakeBat activity became intermittent after its 2024 peak. No public arrest or law enforcement disruption of the operator has established that the service ended, so the accurate position is that the brand declined in prominence rather than that it was dismantled. The wider fake-installer playbook remains active, while newer social-engineering methods such as ClickFix have taken a larger role in initial access. Sekoia's Threat Detection & Research (TDR) team published the primary research on FakeBat in July 2024. The analysis documented the service's forum activity, administration model, distribution clusters, and command-and-control infrastructure. This page focuses on what FakeBat was, how the service worked, what it delivered, and why its delivery model matters beyond the name.

Key takeaways

  • FakeBat was a loader sold as a service. The operators rented it to other cybercriminals through weekly or monthly subscriptions instead of running every campaign themselves.
  • It relied on convincing fake download pages. Paid search ads and poisoned results directed people searching for popular software to lookalike sites serving trojanized installers.
  • Signed installer packages were a premium feature. MSIX packaging and valid digital certificates helped builds appear trustworthy and reduced some Windows reputation warnings.
  • It delivered other people's malware. Observed payloads included infostealers, botnet and banking malware, remote access tooling, and malware that preceded ransomware deployment.
  • The brand declined, but the method continued. Fake installers, malvertising, SEO poisoning, and compromised websites remain relevant delivery techniques.

How FakeBat was sold

From at least December 2022, an operator using the handle Eugenfest, and later Payk_34, advertised FakeBat on Russian-language cybercrime forums. The service was marketed around evasion and delivery success. Customers received access to an administration panel that allowed them to generate builds, select the payload the loader would fetch, and monitor installations.

The panel reported information about infected hosts, including country, operating system, browser, and the software the build was disguised as. Build templates handled the disguise, so a customer without development skills could produce an installer that looked like a real application.

The service also offered a managed distribution option. Customers could pay for landing pages, delivery, and monitoring instead of running those parts themselves. This separation between malware development and distribution reduced the work required from each customer and made the loader function like a criminal software product.

Historical FakeBat pricing

The prices below were reported for September 2023. They describe the historical service model and should not be read as current availability.

FakeBat pricing reported in September 2023
Package Weekly Monthly What it bought
MSI build $1,000 $2,500 The original format, a Windows installer package carrying the loader.
MSIX build $1,500 $4,000 The newer packaging format, introduced to improve delivery success.
MSI with digital signature $1,800 $5,000 The same installer, signed with a valid certificate to look trustworthy.
Managed distribution service Negotiated From $3,000 Landing pages, delivery, and build monitoring handled for the customer.

The pricing reveals where the service delivered value. The premium was attached to the package format and digital signature, not to major changes in the loader's code. Customers were paying for the part that helped a file pass a security prompt and look familiar to a person downloading software.

The operators also limited the number of customers they accepted. A smaller customer base reduced support demands, slowed the spread of the malware, and limited exposure to detection. A loader that appears everywhere becomes easier to identify and less useful to its customers.

How FakeBat reached its targets

Sekoia analysts documented three distribution clusters. They likely represented different customers of the service rather than one centrally managed campaign.

Distribution clusters documented by Sekoia analysts
Cluster How it worked Notable detail
Malvertising and software impersonation Paid search ads and poisoned results sent people to lookalike download pages hosted on typosquatted domains. Pages were near-copies of official homepages, and the software selected often targeted workplace users.
Fake browser updates Compromised websites displayed an update prompt that visitors could not dismiss or click past. Several hundred compromised sites were identified, and the actual number was assessed as considerably higher.
Social engineering on social networks A fake chat application targeting the Web3 community was promoted through legitimate-looking profiles and videos. Downloads required an invitation code, which limited access for automated scanners and researchers.

The impersonated software was selected carefully. Campaigns copied the download pages of remote access tools, note-taking and project management applications, video conferencing software, browsers, developer tools, and creative applications. AnyDesk, Notion, Trello, Zoom, Microsoft Teams, and Google Chrome were among the recurring names.

The choice was practical. These are applications people install on work machines, so a fake installer can reach a valuable account or corporate system. The social-network cluster also used invitation codes. Making a download appear gated and exclusive increased its credibility for the target while limiting access for automated scanners and researchers.

What FakeBat installed

FakeBat itself stole no data. Its purpose was to fetch and run a second-stage payload selected by the customer. Observed payloads included IcedID, Lumma, RedLine, SmokeLoader, SectopRAT, and Ursnif.

These payloads covered several functions:

  • Information stealers: Harvested credentials, session cookies, and cryptocurrency wallet data.
  • Botnet and banking malware: Supported fraud, account takeover, and additional criminal activity.
  • Remote access tooling: Gave an operator hands-on control of the machine.
  • Follow-on access: Initial access brokers could resell the compromised machine to other actors, and some intrusions later ended in ransomware deployment.

This separation is important for incident response. A loader detection does not identify the final objective. The second stage may already have run, and the access may have been sold to another criminal group. The correct response is to investigate the payload and activity that followed rather than treat the loader as a blocked, self-contained malware alert.

Where FakeBat stands now

FakeBat activity peaked in the first half of 2024. After that, observed activity became intermittent, with gaps followed by resurgences. Public reporting has not established an arrest or law enforcement disruption of the operator, so the service should be described as reduced in prominence rather than confirmed defunct.

The surrounding initial-access ecosystem has changed more decisively. Through 2025 and into 2026, ClickFix-style lures that persuade people to run commands themselves became more prominent, and newer loaders moved into the space FakeBat had occupied. The fake-installer approach remains active, but it is now one delivery option among several.

This distinction matters when reading older material. Much of the coverage dates from mid-2024, uses the present tense, and describes FakeBat as a rapidly spreading current threat. The techniques remain useful for detection. The level of urgency depends on the publication date and the evidence available at the time.

What defenders should learn from FakeBat

  • Fake installers exploit intent. Someone searching for software is already planning to run an installer, so the lure asks for an action the target was prepared to take.
  • A valid signature is one signal, not a verdict. Code signing raises the cost for attackers, but certificates can be purchased, stolen, or abused. A signed file still requires context.
  • Search ads and compromised websites are delivery channels. Treating them as an end-user hygiene issue leaves a gap that paid advertising and search manipulation can exploit.
  • Escalate loader detections. A loader hit indicates an intrusion in progress with an unidentified second stage and needs investigation beyond a simple cleanup.
  • Track delivery patterns, not only names. Domains rotate, package formats change, and registration data is anonymized, while the structure of the operation can remain recognizable.
  • Control where users get software. An approved catalog or managed source for common applications removes search engines from the installation path.

Sekoia's research and detection approach

Sekoia's TDR team published the primary research on FakeBat in July 2024. The team identified multiple distribution clusters by following landing pages, installer behavior, and command-and-control patterns rather than waiting for a final payload signature. That work also revealed adjacent clusters using the same fake-installer playbook.

The approach matters because the brand and its infrastructure change faster than the delivery model. A detection strategy that follows only FakeBat domains or file hashes expires quickly. A strategy that watches for a fake software page, a newly downloaded installer, unusual execution from a user download directory, and a second-stage network connection can continue to identify the technique as operators change names and infrastructure.

Expert insight: The delivery model outlived the FakeBat brand

The usual response to a named malware family is to collect its indicators, load them into detection tools, and consider the matter closed. FakeBat shows the limits of that approach. Domains rotated within weeks, the package format changed during the service's life, registration records were deliberately anonymized, and the brand receded while the delivery method spread to other operators. An indicator list built in early 2024 had limited value later that year.

The structure remained stable: rent a loader, dress it up as software people are actively searching for, sign the package so the operating system raises fewer objections, and let another malware family follow. Detection and awareness built around that structure survived the infrastructure changes.

Sekoia is a European cybersecurity vendor whose AI SOC platform correlates endpoint, network, identity, and cloud signals and matches them against behavioral rules mapped to MITRE ATT&CK. Cyber threat intelligence from the in-house TDR team adds context about the delivery infrastructure and the actors using it. That combination helps a security team recognize the intrusion chain rather than wait for a familiar FakeBat file or domain.

The useful question is therefore not only whether FakeBat is active today. It is whether the organization can detect a fake software installer delivering an unknown second stage. That capability remains useful when the malware name, package format, and operator all change.