Skip to content

Dropper

Definition

A malware component whose sole function is to deliver and install a secondary payload. The dropper itself may be a trojan, a malicious document, or a legitimate-looking installer. It commonly deletes itself after execution, leaving the secondary payload as the primary investigative target.

Category
Malware component
Function
Delivers and installs a secondary payload
Common forms
Trojan, malicious document, fake installer
Common behaviour
Self-deletes after execution

Common questions

Why does a dropper self-deleting complicate an investigation?+

Once the dropper removes itself, the initial infection vector and delivery mechanism may only survive in email gateway logs, browser history, or endpoint detection telemetry rather than as a recoverable file on disk, so investigators often have to reconstruct the delivery stage from indirect evidence while the secondary payload remains for direct analysis.

How is a dropper different from a downloader?+

A dropper typically carries the secondary payload embedded within itself and extracts it locally, while a downloader fetches the payload from a remote server after execution. This distinction matters forensically because a downloader's network connection to a command-and-control address can be a recoverable artefact that a self-contained dropper does not generate.

Related terms

Command and Control (C2)
The channel through which an attacker sends instructions to malware on a compromised host and receives data back. C2 channels range from...
Payload
The action the malware performs once active: data encryption (ransomware), credential theft (banking trojan), resource hijacking (cryptominer), or system destruction (wiper). The...
Persistence Mechanism
The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron...
Propagation Mechanism
The method by which malware copies itself to new hosts. Viruses attach to host files; worms exploit network services autonomously; trojans rely...
Rootkit
Malware designed to hide its own presence by subverting the operating system's reporting functions. User-mode rootkits hook API calls; kernel-mode rootkits modify...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.