Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 20:39:28 UTC Home > List all groups > List all tools > List all groups using tool DUNLOADER Tool: DUNLOADER Names DUNLOADER Category Malware Type Loader Description (Trend Micro) The first loader we encountered is DUNLOADER. It’s capable of loading the payloads from either of the locations and decode it in one-byte XOR operations. Information Last change to this tool card: 27 June 2025 Download this tool card in JSON format All groups using tool DUNLOADER Changed Name Country Observed APT groups   Earth Kurma 2020   1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c857d9d1-62de-4f18-b6b9-ca41d83599fc https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c857d9d1-62de-4f18-b6b9-ca41d83599fc Page 1 of 1