The new downloader stands out from the rest due to its ability to receive multiple commands in a single request. This gives the threat actors the ability to drop several malware payloads to the infected system with a single request. This makes the malware downloader extensible, and much more efficient.
RockLoader has been distributed through spam emails with JS attachments, as well as malicious documents.
ThreatSTOP customers are protected from RockLoader.