Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 15:41:22 UTC Home > List all groups > List all tools > List all groups using tool BeaconLoader Tool: BeaconLoader Names BeaconLoader Category Malware Type Loader Description (Positive Technologies) BeaconLoader is uploaded using DLL Hijacking. At the first stage, the library receives the addresses of the functions and libraries necessary for its operation. Then, it checks the name of the parent process and the privilege type (for further work, the SYSTEM type and names msdtc.exe, msdtc.exe.mui, and vmtoolsd.exe are required). Information Last change to this tool card: 02 November 2021 Download this tool card in JSON format All groups using tool BeaconLoader Changed Name Country Observed APT groups ChamelGang 2021-Jun 2023 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=93c315eb-5c5a-4e9c-8b31-14216ff9a407 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=93c315eb-5c5a-4e9c-8b31-14216ff9a407 Page 1 of 1