Glossary

Dropper

A dropper is a delivery system. It sneaks onto your computer looking harmless, then 'drops' the real malware. The dropper might be detected, but by then the damage is delivered.

What is Dropper?

Malware designed to install other malware on a system, often avoiding detection by appearing legitimate initially.

Why Should You Care?

Droppers enable multi-stage attacks where initial detection or removal of the dropper itself doesn't stop the threat—the payload malware (banking trojans, ransomware, or info-stealers) is already executing independently. This two-phase delivery mechanism allows attackers to bypass endpoint detection by obfuscating the final payload, making incident response significantly harder and giving attackers a foothold to deploy additional tools like data exfiltration malware or ransomware before defenders detect the secondary threat.

Is your business exposed?

Real-World Example

In 2020–2021, Emotet functioned as a dropper for the TrickBot banking trojan, which in turn led to Ryuk ransomware. Emotet spread through malicious email attachments; once installed, it silently downloaded TrickBot. Security teams removing Emotet from systems often discovered TrickBot was already exfiltrating credentials while Ryuk encrypted critical files, resulting in a "steal-then-ransom" attack where data theft and encryption happened in separate stages, making containment and recovery significantly more difficult.

How to Protect Against Dropper

  1. 1.

    Block macro execution in Office documents

  2. 2.

    Use email sandboxing for attachments

Related Terms

Malware, Trojan, Loader

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required