Skip to content

PrivateLoader

PrivateLoader is a malicious loader family first identified in 2021 and commonly associated with pay-per-install distribution activity.

Profile source: Mallory opens in a new tab

PrivateLoader

Family profile

PrivateLoader is a malicious loader family first identified in 2021 and commonly associated with pay-per-install distribution activity. It is used to download and execute a wide range of follow-on malware, including stealers, RATs, spyware, rootkits, proxy bot malware, cryptominers, and ransomware. Reported payloads and associated malware families include RedLine, DCRat, RaccoonStealer, Lumma/LummaC2, RisePro, Amadey, StealC, Glupteba, Tofsee-related activity, Socks5Systemz, and STOP/DJVU ransomware. PrivateLoader has also been referenced in campaigns targeting the robotics industry.

Observed infection vectors include cracked or pirated software lures, fake installers, drive-by downloads, phishing or social distribution, file-sharing sites, and abuse of trusted hosting platforms such as Discordโ€™s CDN for next-stage payload retrieval. In one documented multi-stage cracked-software campaign, a trojanized setup.exe masquerading as a Logitech installer launched PrivateLoader, which then communicated over HTTP with 185.216.70.235 and 195.20.16.45 using requests to /api/tracemap.php and /api/firegate.php, modified Chrome extension files resulting in the K Searches extension being added, and dropped Amadey payloads to C:\Users\admin\Pictures\Minor Policy\5RfuRxo3fpxiWkD42DRCixRe.exe and C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\J0KBFYBW\build2[1].exe.

PrivateLoader has been linked to broader cybercrime ecosystems rather than a single exclusive payload set. It has been described as powering or participating in pay-per-install services and has been used in campaigns tied to Water Orthrus/CopperPhish distribution, Glupteba delivery chains, Lumma infections, Socks5Systemz standalone deployment, and malware delivery via Discord CDN. High-confidence indicators directly mentioned in the content include the HTTP paths /api/tracemap.php and /api/firegate.php, the IPs 185.216.70.235 and 195.20.16.45, and a CopperPhish-chain PrivateLoader sample with SHA-256 48211c6f957c2ad024441be3fc32aecd7c317dfc92523b0a675c0cfec86ffdd9.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 6, 2026
Feed role
C2 / Distribution
Host form
5 IP / 20 hostnames

Leading locations

  • US17
  • RU4
  • IE2
  • BG1
  • NL1

Leading providers

  • Amazon.com, Inc.9
  • Amazon.com, Inc.6
  • Akamai Connected Cloud2
  • Smart Technology LLC2
  • FOTONTELECOM ISP1
  • Google LLC1

Infrastructure traits

  • Hosting 24
  • Vpn 3

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Silver Fox

The campaign uses multiple malware families under a single operational umbrella: SHA256 (truncated) Filename Signature First Seen 95e30af4... PoisonX.exe PrivateLoader 2026-03-10

MITRE ATT&CK

PrivateLoader in ATT&CK

7 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.