Skip to content

HijackLoader

HijackLoader is a modular Windows malware loader and packer used to stage and deploy a wide range of follow-on payloads, especially information stealers and remote-access malware.

Profile source: Mallory opens in a new tab

HijackLoader

Family profile

HijackLoader is a modular Windows malware loader and packer used to stage and deploy a wide range of follow-on payloads, especially information stealers and remote-access malware. It has been observed in multiple delivery ecosystems, including ClickFix social-engineering chains, fake software and pirated-software lures, malicious game or installer packages, and DLL side-loading abuse involving legitimate signed applications. Security reporting also refers to related variants or naming overlaps such as IDAT Loader and GHOSTPULSE in some detections and clustering.

The malware is designed for flexible payload delivery and strong defense evasion. Observed samples use DLL hijacking or side-loading, module stomping, process injection, thread-context hijacking, transacted hollowing, syscall indirection, stack spoofing, API hashing, and unhooking of ntdll to reduce visibility to security tools. HijackLoader commonly decrypts staged configuration and payload data from auxiliary files, reconstructs modules in memory, and executes later stages without relying on straightforward on-disk payload placement. Some variants use SEC_IMAGE section mapping and other stealth-oriented injection approaches associated with modern loader tradecraft.

HijackLoader supports persistence and post-compromise orchestration. Reported samples have copied themselves to persistent locations, relaunched via legitimate binaries, created startup shortcuts or scheduled tasks, and altered execution paths depending on the presence of security products. Anti-analysis features documented across samples include virtualization and sandbox checks, timing checks, hardware and memory profiling, locale or regional filtering, hostname inspection, and conditional execution logic driven by configuration modules.

The loader is frequently used as an initial execution platform for other malware families rather than as the final objective itself. Public reporting has linked HijackLoader delivery chains to payloads including Lumma Stealer, Vidar Stealer, DeerStealer, StealC, Amadey, XMRig, Remcos, xWorm, DanaBot, Rhadamanthys, Tofsee, and other stealers or RATs. It has also been observed in campaigns associated with APT-C-36 and in broader criminal distribution operations using cracked software, fake CAPTCHA or verification prompts, and trojanized installers.

HijackLoader primarily targets Windows systems and is notable for combining loader-as-a-service-style flexibility with layered evasion, modular staging, and abuse of trusted binaries to deliver secondary malware at scale.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
18 IP / 45 hostnames

Leading locations

  • US23
  • DE8
  • FI4
  • NL4
  • GB3
  • RU3
  • CA1
  • CN1
  • CO1
  • ES1
  • FR1
  • IN1

Leading providers

  • Cloudflare, Inc.12
  • Hetzner Online GmbH5
  • Amazon.com, Inc.3
  • Omegatech LTD3
  • Amazon.com, Inc.2
  • FEMO IT SOLUTIONS LIMITED2

Infrastructure traits

  • Hosting 50
  • Anycast 13

Samples

Recent associated samples

Reported operators

Threat actors

5 named in public reporting
APT-C-36

APT-C-36 has used side-loading to execute the HijackLoader payload.

UAC-0184

The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.

MB-0005

The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.

PLUMP SPIDER

The infrastructure graph generated from the correlation of indicators identified in the campaign reveals a complex network of relationships... through this, we note similarities with the already well-known “HijackLoader.”

EncryptHub

“...EncryptHub added to the game files the HijackLoader malware (CVKRUTNP.exe), which establishes persistence on the victim device and downloads the Vidar infostealer (v9d9d.exe).”

MITRE ATT&CK

HijackLoader in ATT&CK

57 distinct techniques

Techniques

57 techniques
T1105 Ingress Tool Transfer T1204.002 Malicious File T1129 Shared Modules T1055 Process Injection T1055.002 Portable Executable Injection T1055.001 Dynamic-link Library Injection T1106 Native API T1620 Reflective Code Loading T1070.004 File Deletion T1562.001 Disable or Modify Tools T1140 Deobfuscate/Decode Files or Information T1036 Masquerading T1574 Hijack Execution Flow T1027 Obfuscated Files or Information T1548.002 Bypass User Account Control T1574.001 DLL T1622 Debugger Evasion T1204 User Execution T1059.001 PowerShell T1497 Virtualization/Sandbox Evasion T1566 Phishing T1055.013 Process Doppelgänging T1055.003 Thread Execution Hijacking T1218.007 Msiexec T1059 Command and Scripting Interpreter T1115 Clipboard Data T1497.001 System Checks T1027.007 Dynamic API Resolution T1059.003 Windows Command Shell T1055.012 Process Hollowing T1218 System Binary Proxy Execution T1562 Impair Defenses T1548 Abuse Elevation Control Mechanism T1547.009 Shortcut Modification T1197 BITS Jobs T1057 Process Discovery T1014 Rootkit T1543 Create or Modify System Process T1127.001 MSBuild T1566.001 Spearphishing Attachment T1027.003 Steganography T1027.009 Embedded Payloads T1566.002 Spearphishing Link T1027.001 Binary Padding T1583 Acquire Infrastructure T1218.005 Mshta T1583.001 Domains T1608.006 SEO Poisoning T1053.005 Scheduled Task T1027.002 Software Packing T1189 Drive-by Compromise T1555 Credentials from Password Stores T1195.002 Compromise Software Supply Chain T1059.006 Python T1601.001 Patch System Image T1583.006 Web Services T1195 Supply Chain Compromise

Reporting

Research mentioning HijackLoader

Aug 24
Malware News

Tracking PavinLoader across ClickFix and fake download campaigns - Malware News - Malware Analysis, News and Indicators

Researchers linked PavinLoader, a multi-stage .NET malware loader, to several intrusion chains that used ClickFix lures, fake software downloads, and malicious RenPy packages to infect victims. Across the campaigns, operators relied on trojanized and heavily obfuscated .NET DLLs, along with abuse of MSBuild through .csproj and .bat files, to execute later stages while complicating analysis and detection. The loader retrieved command-and-control details using EtherHiding, including Binance Smart Chain RPC calls to pull infrastructure data from blockchain-hosted content, and then fetched additional payloads. In observed cases, PavinLoader delivered Amatera Stealer and at times HijackLoader, while also using anti-analysis and anti-forensics measures such as AMSI/ETW-related evasion strings, virtualization checks, locale filtering, and infrastructure-provider checks; shared artifacts and builder-like scripts led researchers to assess that it may be operated as a Loader-as-a-Service, though no commercial panel or offering was confirmed.

Aug 24
Malwarebytes Labs

Tracking PavinLoader across ClickFix and fake download campaigns | Malwarebytes

Jul 21
Cyberveille

Faux jeux distribuent Amatera Stealer via RenPy Loader, MSBuild et EtherHiding | CyberVeille

Threat actors are distributing fake games, mods, cracks, and software installers that abuse the legitimate Ren’Py visual novel engine to launch a multi-stage malware chain ending in Amatera Stealer. Researchers said the initial RenPy Loader (also called RenEngine Loader) extracts an encrypted ZIP archive, runs a BAT file through forfiles.exe, and then uses MSBuild to execute a trojanized .NET component, advancing the infection through several downloader and anti-analysis stages. The later stages include anti-sandbox checks, removal of the Mark-of-the-Web via the Zone.Identifier alternate data stream, and reflective loading of a malicious Nancy .NET component before the stealer is decrypted and executed. The campaigns were hosted on fake download sites, itch.io pages, and file-sharing services, and used the EtherHiding technique to pull command-and-control details from blockchain data, complicating infrastructure takedowns and attribution; published indicators include malicious domains, IP addresses, and file hashes tied to the downloader, loader, and final payload.

Jul 20
Malware News

Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding - Malware News - Malware Analysis, News and Indicators

Jul 20
Malwarebytes Labs

Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding | Malwarebytes

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.