Last seven days
- First activity
- Aug 30, 2026
- Last activity
- Aug 30, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 0 hostnames
PrivateLoader is a Windows malware loader operated as a pay-per-install distribution service that has been active since at least early 2021.
Profile source: Mallory opens in a new tabPrivateLoader
PrivateLoader is a Windows malware loader operated as a pay-per-install distribution service that has been active since at least early 2021. It is commonly associated with SEO-poisoned and cracked-software distribution chains in which victims download password-protected archives and installers masquerading as pirated or free software. The service has been used by multiple threat actors to deliver a broad range of follow-on payloads, especially information stealers, but also banking trojans, remote-access trojans, spambots, proxy bot malware, cryptominers, secondary loaders, and ransomware.
PrivateLoader functions as a multi-stage loader with components that download and execute additional modules and payloads. Reported behavior includes persistence through scheduled tasks, self-updating, repeated reinfection activity, anti-analysis measures, and impairment of defenses including Windows Defender tampering. It has also been observed performing system and environment checks, using encrypted or obfuscated HTTP communications, and selectively delivering payloads based on victim attributes such as geography, installed software, and other environmental characteristics.
PrivateLoader has been linked to large-scale crimeware distribution and has delivered families including RedLine, RisePro, SmokeLoader, Amadey, IcedID, Tofsee, Socks5Systemz, STOP/DJVU, Vidar, Raccoon, DanaBot, QakBot, Dridex, and others. In some observed chains, it acted as the primary orchestrator for multi-malware infections that combined credential theft, browser-data theft, proxy-bot deployment, cryptomining, persistence, and eventual ransomware execution. It has also been used to distribute proxy botnets and spambots, underscoring its role as a general-purpose criminal malware delivery platform rather than a single-purpose payload.
Telemetry and reporting indicate worldwide victimization, with notable prevalence in parts of Asia, Africa, and South America. Researchers have described PrivateLoader as a high-volume loader ecosystem responsible for very large infection counts and sustained daily install rates. Its operational model, broad customer base, and recurring use in cracked-software ecosystems make it a significant enabler of commodity cybercrime on Windows systems.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
PrivateLoader is a loader from a pay-per-install malware distribution service that has been utilized to distribute info stealers, banking trojans, loaders, spambots, rats, miners and ransomware on Windows machines.
PrivateLoader is one of the most widely used loaders in 2022. It is used by a Pay-Per-Install service to deploy multiple malicious payloads on the infected hosts. First observed in May 2021, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads.
The campaign uses multiple malware families under a single operational umbrella: SHA256 (truncated) Filename Signature First Seen 95e30af4... PoisonX.exe PrivateLoader 2026-03-10
MITRE ATT&CK
Reporting
Silent Push reported that devices enrolled in PEER2PROFIT are being monetized through the commercial proxy service ASTROPROXY, effectively turning user and potentially corporate endpoints into residential proxy exit nodes. Researchers validated the link by enrolling a controlled device in PEER2PROFIT and later observing its IP address offered in ASTROPROXY’s residential pool. Because the software is typically installed with user consent and is not generally classified as malware, the activity can evade traditional enterprise security controls while exposing an organization’s IP space to abuse, fraud investigations, and reputational damage. During a 72-hour enumeration effort, the researchers identified 117,224 unique IPs across ASTROPROXY’s residential, mobile, and datacenter proxy pools, with the residential pool adding more than 1,000 new IPs per hour. The report also found that ASTROPROXY’s internal-IP filtering could be bypassed by using a DNS name that resolves to an internal address, potentially allowing proxy subscribers to reach internal resources such as router management interfaces through enrolled nodes. The findings highlight that bandwidth-sharing applications can create internal exposure and that proactive enumeration of proxy infrastructure may be more effective than reactive reputation-based blocking.
Threat actors used fake Facebook job advertisements and impersonation content, including lures themed around Amazon CEO Andy Jassy and DocuSign, to distribute the Windows information stealer Ov3r_Stealer. Trustwave SpiderLabs found victims were redirected to Discord-hosted .url shortcut files and, in some cases, weaponized PDFs, which triggered a multi-stage infection chain involving control.exe, malicious .cpl loaders, PowerShell scripts fetched from GitHub, and a final DLL sideloading payload delivered from a remote SMB share. Once installed, Ov3r_Stealer established persistence through scheduled tasks running every 90 minutes and harvested browser credentials, crypto wallets, FTP and Discord data, documents, and system information before exfiltrating the data to attacker-controlled Telegram bots and channels. Researchers said the malware was under active development, with alternate delivery methods including HTML smuggling, SVG smuggling, and LNK masquerading, and noted strong similarities to the open-source Phemedrone Stealer; the activity was linked to aliases including Liu Kong, John Macollan, MR Meta, and MeoBlackA, with indications the operator may be offering the malware as a service.
Researchers reported that the long-running Tofsee botnet, historically known as a modular spambot, was being distributed through the PrivateLoader malware loader tied to the ruzki pay-per-install service. While earlier reporting highlighted Tofsee’s aggressive spam activity, newer observations showed the botnet using infected systems primarily for web traffic proxying and cryptocurrency mining, with only a smaller share of activity linked to spam operations. Analysis of Tofsee’s downloaded components identified active proxy and miner plugins, including HTTP(S) and SOCKS backconnect traffic and some spam-related POST requests routed through likely compromised websites. The mining module was configured to mine Masari (MSR) through fastpool.xyz, and researchers estimated the botnet had generated about 200,000 MSR. Sampled telemetry indicated a global infection footprint, with India accounting for roughly 33% of observed infections in the dataset.
Security researchers detailed a lightweight method for identifying IcedID command-and-control infrastructure without relying on full malware reverse engineering, using a distinctive self-signed TLS certificate repeatedly found on the malware’s servers. The certificate commonly carries issuer and subject values including CN=localhost, C=AU, ST=Some-State, and O=Internet Widgits Pty Ltd, allowing defenders to search internet-wide scan data for likely matches and rapidly narrow candidate hosts tied to the banking trojan. The infrastructure was then validated by reproducing IcedID’s certificate verification logic, in which the malware hashes the certificate public key with FNV-1a 32-bit and compares the result to the certificate serial number, sometimes after XOR with 0x384A2414. Using that process, researchers confirmed 52 IcedID servers and found the infrastructure commonly exposed ports 443, 80, and 22, frequently ran Debian and nginx, and was concentrated in Romania, the United States, and Germany; related reporting on IcedID and its loader activity underscores the malware’s continued use in credential theft and banking-focused intrusions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.