In this blog post, we will explore the extended functionalities of Mortar Loader and how it can be weaponized and replicated with different attack profiles such as DLL sideloading and malicious Office add-ins.
Mortar Loader is a tool designed to help security professionals and Red Teams evade detection in operations by loading encrypted shellcode and PE executables and using various evasion tactics.
Its latest version was released last year and received positive feedback from the security community after having been presented publicly. Surprisingly, at the time of writing this blog post, Mortar Loader has not been flagged as malicious by several well-known security solutions. This could be because it uses less common programming languages, particularly Pascal. As indicated by the ‘Any.Run’ security team, using less common programming languages makes it more difficult to detect.