Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:44:25 UTC Home > List all groups > List all tools > List all groups using tool CoreLoader Tool: CoreLoader Names CoreLoader Category Malware Type Loader Description (Kaspersky) CoreLoader, the last malware we found associated to this set of activity, is a simple shellcode loader which performs anti-analysis and loads additional code from a file named WsmRes.xsl. Again, this specific file eluded our attempts to catch it but we suspect it to be, one way or another, related to FoundCore (described in the previous section). Information Last change to this tool card: 15 May 2021 Download this tool card in JSON format All groups using tool CoreLoader Changed Name Country Observed APT groups Goblin Panda, Cycldek, Conimes 2013-Jun 2020 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=904bb94c-6e68-43a6-913a-ce026f9de390 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=904bb94c-6e68-43a6-913a-ce026f9de390 Page 1 of 1