Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 8 hostnames
HijackLoader, also known as IDAT Loader and sometimes DOILoader, is a modular Windows malware loader used to stage and deploy a wide range of follow-on payloads.
Profile source: Mallory opens in a new tabHijackLoader
HijackLoader, also known as IDAT Loader and sometimes DOILoader, is a modular Windows malware loader used to stage and deploy a wide range of follow-on payloads. It is designed to provide operators with flexible execution, in-memory assembly of components, and delivery of additional malware families rather than serving as the final objective itself. Reported downstream payloads associated with HijackLoader campaigns include information stealers such as Vidar, Lumma Stealer, Amatera Stealer, DeerStealer, and StealC, as well as remote-access malware including SnappyClient and reused banking malware such as Carbanak in modern delivery chains.
A defining characteristic of HijackLoader is its use of encoded or steganographic containers, especially data embedded in image-related structures such as PNG IDAT chunks, which are reconstructed and decompressed at runtime. Analyses describe bundles assembled from multiple modules and decrypted only in memory, complicating static inspection and enabling operators to swap final payloads between campaigns. Observed execution chains also show HijackLoader being launched through DLL sideloading with signed host applications, shellcode stages, and process hollowing or similar memory-execution techniques to run the next-stage malware under legitimate process cover.
HijackLoader appears across multiple intrusion patterns. It has been delivered through ClickFix and other paste-and-run social-engineering lures that trick users into executing malicious PowerShell commands, through fake verification pages impersonating major web services, through trojanized or fake software installers, through cracked software and fake game or mod downloads, and through targeted spearphishing attachments themed as software updates. It has also been observed as a payload delivered by other malware distribution ecosystems and loaders, including RenPy Loader, StealC-linked activity, and compromised website traffic-distribution campaigns.
Behavior associated with HijackLoader includes defense evasion through binary bloating, anti-analysis measures, use of trusted or signed binaries as sideload hosts, reflective or in-memory loading, and installation of persistence in some chains. Its role in the intrusion lifecycle is primarily post-compromise staging and payload delivery, but individual campaigns have also shown it participating in execution orchestration and handoff to credential theft, session theft, remote access, or broader post-exploitation tooling. Financially motivated cybercrime operations are the most consistently associated users, including MaaS-style ecosystems and campaigns targeting enterprises, consumers, and in some cases financial institutions.
C2 tracking
Derp observations, rolling seven-day window
Samples
67cd5f1b19d33786a9f73b630357cce0d90d6771590ccb965fb331ffc6d4fb94 73fc2d3057331b8382c4e0e833f495c2843bfb36a48d7e765ddbc1be241e5a67 d2555e5f817810e4839bb5c163514cf4807b5f9878708a519d68e52f5d48e7ab dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9 f1fe7bb2031c73328ccb32730d319b8ba0dabca108addd1135468a75fed36b8f 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30955adfb864533f1d6a46b25f02aa79c5c5891d0b536eb9da9d33bcaa1061db 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 7fe76ccceaec33d07e90e96ac144be83ed622c8af8b134d7429020e476cf4716 b20f39fc00d242e706b6c30367ad811c676e0575050a4ec2f30104b696944b49 Reported operators
The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.
The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.
The infrastructure graph generated from the correlation of indicators identified in the campaign reveals a complex network of relationships... through this, we note similarities with the already well-known โHijackLoader.โ
โ...EncryptHub added to the game files the HijackLoader malware (CVKRUTNP.exe), which establishes persistence on the victim device and downloads the Vidar infostealer (v9d9d.exe).โ
MITRE ATT&CK
Reporting
Threat actors are distributing fake games, mods, cracks, and software installers that abuse the legitimate RenโPy visual novel engine to launch a multi-stage malware chain ending in Amatera Stealer. Researchers said the initial RenPy Loader (also called RenEngine Loader) extracts an encrypted ZIP archive, runs a BAT file through forfiles.exe, and then uses MSBuild to execute a trojanized .NET component, advancing the infection through several downloader and anti-analysis stages. The later stages include anti-sandbox checks, removal of the Mark-of-the-Web via the Zone.Identifier alternate data stream, and reflective loading of a malicious Nancy .NET component before the stealer is decrypted and executed. The campaigns were hosted on fake download sites, itch.io pages, and file-sharing services, and used the EtherHiding technique to pull command-and-control details from blockchain data, complicating infrastructure takedowns and attribution; published indicators include malicious domains, IP addresses, and file hashes tied to the downloader, loader, and final payload.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.