Dropper
Definition
A malware component whose sole function is to deliver and install a secondary payload. The dropper itself may be a trojan, a malicious document, or a legitimate-looking installer. It commonly deletes itself after execution, leaving the secondary payload as the primary investigative target.
- Category
- Malware component
- Function
- Delivers and installs a secondary payload
- Common forms
- Trojan, malicious document, fake installer
- Common behaviour
- Self-deletes after execution
Common questions
Why does a dropper self-deleting complicate an investigation?+
Once the dropper removes itself, the initial infection vector and delivery mechanism may only survive in email gateway logs, browser history, or endpoint detection telemetry rather than as a recoverable file on disk, so investigators often have to reconstruct the delivery stage from indirect evidence while the secondary payload remains for direct analysis.
How is a dropper different from a downloader?+
A dropper typically carries the secondary payload embedded within itself and extracts it locally, while a downloader fetches the payload from a remote server after execution. This distinction matters forensically because a downloader's network connection to a command-and-control address can be a recoverable artefact that a self-contained dropper does not generate.
Related terms
- Command and Control (C2)
- The channel through which an attacker sends instructions to malware on a compromised host and receives data back. C2 channels range from...
- Payload
- The action the malware performs once active: data encryption (ransomware), credential theft (banking trojan), resource hijacking (cryptominer), or system destruction (wiper). The...
- Persistence Mechanism
- The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron...
- Propagation Mechanism
- The method by which malware copies itself to new hosts. Viruses attach to host files; worms exploit network services autonomously; trojans rely...
- Rootkit
- Malware designed to hide its own presence by subverting the operating system's reporting functions. User-mode rootkits hook API calls; kernel-mode rootkits modify...