Skip to content

HijackLoader

HijackLoader, also known as IDAT Loader and sometimes DOILoader, is a modular Windows malware loader used to stage and deploy a wide range of follow-on payloads.

Profile source: Mallory opens in a new tab

HijackLoader

Family profile

HijackLoader, also known as IDAT Loader and sometimes DOILoader, is a modular Windows malware loader used to stage and deploy a wide range of follow-on payloads. It is designed to provide operators with flexible execution, in-memory assembly of components, and delivery of additional malware families rather than serving as the final objective itself. Reported downstream payloads associated with HijackLoader campaigns include information stealers such as Vidar, Lumma Stealer, Amatera Stealer, DeerStealer, and StealC, as well as remote-access malware including SnappyClient and reused banking malware such as Carbanak in modern delivery chains.

A defining characteristic of HijackLoader is its use of encoded or steganographic containers, especially data embedded in image-related structures such as PNG IDAT chunks, which are reconstructed and decompressed at runtime. Analyses describe bundles assembled from multiple modules and decrypted only in memory, complicating static inspection and enabling operators to swap final payloads between campaigns. Observed execution chains also show HijackLoader being launched through DLL sideloading with signed host applications, shellcode stages, and process hollowing or similar memory-execution techniques to run the next-stage malware under legitimate process cover.

HijackLoader appears across multiple intrusion patterns. It has been delivered through ClickFix and other paste-and-run social-engineering lures that trick users into executing malicious PowerShell commands, through fake verification pages impersonating major web services, through trojanized or fake software installers, through cracked software and fake game or mod downloads, and through targeted spearphishing attachments themed as software updates. It has also been observed as a payload delivered by other malware distribution ecosystems and loaders, including RenPy Loader, StealC-linked activity, and compromised website traffic-distribution campaigns.

Behavior associated with HijackLoader includes defense evasion through binary bloating, anti-analysis measures, use of trusted or signed binaries as sideload hosts, reflective or in-memory loading, and installation of persistence in some chains. Its role in the intrusion lifecycle is primarily post-compromise staging and payload delivery, but individual campaigns have also shown it participating in execution orchestration and handoff to credential theft, session theft, remote access, or broader post-exploitation tooling. Financially motivated cybercrime operations are the most consistently associated users, including MaaS-style ecosystems and campaigns targeting enterprises, consumers, and in some cases financial institutions.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Initial Access
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
8 IP / 8 hostnames

Leading locations

  • DE4
  • NL2
  • CN1
  • CO1
  • FI1
  • IN1
  • LU1
  • RU1
  • US1

Leading providers

  • Ghosty Networks LLC2
  • Omegatech LTD2
  • CHINA UNICOM China169 Backbone1
  • FEMO IT SOLUTIONS LIMITED1
  • Hetzner Online GmbH1
  • HIVELOCITY, Inc.1

Infrastructure traits

  • Hosting 11

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
UAC-0184

The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.

MB-0005

The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.

PLUMP SPIDER

The infrastructure graph generated from the correlation of indicators identified in the campaign reveals a complex network of relationships... through this, we note similarities with the already well-known โ€œHijackLoader.โ€

EncryptHub

โ€œ...EncryptHub added to the game files the HijackLoader malware (CVKRUTNP.exe), which establishes persistence on the victim device and downloads the Vidar infostealer (v9d9d.exe).โ€

MITRE ATT&CK

HijackLoader in ATT&CK

38 distinct techniques

Reporting

Research mentioning HijackLoader

Jul 21
Cyberveille

Faux jeux distribuent Amatera Stealer via RenPy Loader, MSBuild et EtherHiding | CyberVeille

Threat actors are distributing fake games, mods, cracks, and software installers that abuse the legitimate Renโ€™Py visual novel engine to launch a multi-stage malware chain ending in Amatera Stealer. Researchers said the initial RenPy Loader (also called RenEngine Loader) extracts an encrypted ZIP archive, runs a BAT file through forfiles.exe, and then uses MSBuild to execute a trojanized .NET component, advancing the infection through several downloader and anti-analysis stages. The later stages include anti-sandbox checks, removal of the Mark-of-the-Web via the Zone.Identifier alternate data stream, and reflective loading of a malicious Nancy .NET component before the stealer is decrypted and executed. The campaigns were hosted on fake download sites, itch.io pages, and file-sharing services, and used the EtherHiding technique to pull command-and-control details from blockchain data, complicating infrastructure takedowns and attribution; published indicators include malicious domains, IP addresses, and file hashes tied to the downloader, loader, and final payload.

Jul 20
Malware News

Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding - Malware News - Malware Analysis, News and Indicators

Jul 20
Malwarebytes Labs

Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding | Malwarebytes

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.