Campo is a spanish word meaning countryside, this word is referred in all URL this malware access, hence the name Campo. Campo loader is a simple and effective malware responsible for spreading other malware. It is known as the first stage payload for TrickBot
, Gozi, and Zloader. Once its executed, it contacted its C2 server for the payload if the incoming request meet a certain criteria then the malware will either is delivered. If the request does not meet the required specifications
the request is redirected to either Yahoo or UPS websites.
Campo Loader Signatures
Campo Loader Download