Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 18 IP / 45 hostnames
HijackLoader is a modular Windows malware loader and packer used to stage and deploy a wide range of follow-on payloads, especially information stealers and remote-access malware.
Profile source: Mallory opens in a new tabHijackLoader
HijackLoader is a modular Windows malware loader and packer used to stage and deploy a wide range of follow-on payloads, especially information stealers and remote-access malware. It has been observed in multiple delivery ecosystems, including ClickFix social-engineering chains, fake software and pirated-software lures, malicious game or installer packages, and DLL side-loading abuse involving legitimate signed applications. Security reporting also refers to related variants or naming overlaps such as IDAT Loader and GHOSTPULSE in some detections and clustering.
The malware is designed for flexible payload delivery and strong defense evasion. Observed samples use DLL hijacking or side-loading, module stomping, process injection, thread-context hijacking, transacted hollowing, syscall indirection, stack spoofing, API hashing, and unhooking of ntdll to reduce visibility to security tools. HijackLoader commonly decrypts staged configuration and payload data from auxiliary files, reconstructs modules in memory, and executes later stages without relying on straightforward on-disk payload placement. Some variants use SEC_IMAGE section mapping and other stealth-oriented injection approaches associated with modern loader tradecraft.
HijackLoader supports persistence and post-compromise orchestration. Reported samples have copied themselves to persistent locations, relaunched via legitimate binaries, created startup shortcuts or scheduled tasks, and altered execution paths depending on the presence of security products. Anti-analysis features documented across samples include virtualization and sandbox checks, timing checks, hardware and memory profiling, locale or regional filtering, hostname inspection, and conditional execution logic driven by configuration modules.
The loader is frequently used as an initial execution platform for other malware families rather than as the final objective itself. Public reporting has linked HijackLoader delivery chains to payloads including Lumma Stealer, Vidar Stealer, DeerStealer, StealC, Amadey, XMRig, Remcos, xWorm, DanaBot, Rhadamanthys, Tofsee, and other stealers or RATs. It has also been observed in campaigns associated with APT-C-36 and in broader criminal distribution operations using cracked software, fake CAPTCHA or verification prompts, and trojanized installers.
HijackLoader primarily targets Windows systems and is notable for combining loader-as-a-service-style flexibility with layered evasion, modular staging, and abuse of trusted binaries to deliver secondary malware at scale.
C2 tracking
Derp observations, rolling seven-day window
Samples
211a0aa3cbc77439136e0255946baf55e9bce1bee9dfa34884673ba0330f11f3 3b6393dc2c7a9db73f7dfdd41edfbafd3ebd1dd31b90230d926c2725f9852c40 7123e1514b939b165985560057fe3c761440a9fff9783a3b84e861fd2888d4ab 7ea2078158ff32452de41964f7eb4014a291182024c9126341a0690d2271b832 db452315716835876c7b70eeeb04b85dc1528db37ba47564704b9095c22f8954 1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 Reported operators
APT-C-36 has used side-loading to execute the HijackLoader payload.
The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.
The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.
The infrastructure graph generated from the correlation of indicators identified in the campaign reveals a complex network of relationships... through this, we note similarities with the already well-known “HijackLoader.”
“...EncryptHub added to the game files the HijackLoader malware (CVKRUTNP.exe), which establishes persistence on the victim device and downloads the Vidar infostealer (v9d9d.exe).”
MITRE ATT&CK
Reporting
Researchers linked PavinLoader, a multi-stage .NET malware loader, to several intrusion chains that used ClickFix lures, fake software downloads, and malicious RenPy packages to infect victims. Across the campaigns, operators relied on trojanized and heavily obfuscated .NET DLLs, along with abuse of MSBuild through .csproj and .bat files, to execute later stages while complicating analysis and detection. The loader retrieved command-and-control details using EtherHiding, including Binance Smart Chain RPC calls to pull infrastructure data from blockchain-hosted content, and then fetched additional payloads. In observed cases, PavinLoader delivered Amatera Stealer and at times HijackLoader, while also using anti-analysis and anti-forensics measures such as AMSI/ETW-related evasion strings, virtualization checks, locale filtering, and infrastructure-provider checks; shared artifacts and builder-like scripts led researchers to assess that it may be operated as a Loader-as-a-Service, though no commercial panel or offering was confirmed.
Threat actors are distributing fake games, mods, cracks, and software installers that abuse the legitimate Ren’Py visual novel engine to launch a multi-stage malware chain ending in Amatera Stealer. Researchers said the initial RenPy Loader (also called RenEngine Loader) extracts an encrypted ZIP archive, runs a BAT file through forfiles.exe, and then uses MSBuild to execute a trojanized .NET component, advancing the infection through several downloader and anti-analysis stages. The later stages include anti-sandbox checks, removal of the Mark-of-the-Web via the Zone.Identifier alternate data stream, and reflective loading of a malicious Nancy .NET component before the stealer is decrypted and executed. The campaigns were hosted on fake download sites, itch.io pages, and file-sharing services, and used the EtherHiding technique to pull command-and-control details from blockchain data, complicating infrastructure takedowns and attribution; published indicators include malicious domains, IP addresses, and file hashes tied to the downloader, loader, and final payload.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.