Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 5 IP / 20 hostnames
PrivateLoader is a malicious loader family first identified in 2021 and commonly associated with pay-per-install distribution activity.
Profile source: Mallory opens in a new tabPrivateLoader
PrivateLoader is a malicious loader family first identified in 2021 and commonly associated with pay-per-install distribution activity. It is used to download and execute a wide range of follow-on malware, including stealers, RATs, spyware, rootkits, proxy bot malware, cryptominers, and ransomware. Reported payloads and associated malware families include RedLine, DCRat, RaccoonStealer, Lumma/LummaC2, RisePro, Amadey, StealC, Glupteba, Tofsee-related activity, Socks5Systemz, and STOP/DJVU ransomware. PrivateLoader has also been referenced in campaigns targeting the robotics industry.
Observed infection vectors include cracked or pirated software lures, fake installers, drive-by downloads, phishing or social distribution, file-sharing sites, and abuse of trusted hosting platforms such as Discordโs CDN for next-stage payload retrieval. In one documented multi-stage cracked-software campaign, a trojanized setup.exe masquerading as a Logitech installer launched PrivateLoader, which then communicated over HTTP with 185.216.70.235 and 195.20.16.45 using requests to /api/tracemap.php and /api/firegate.php, modified Chrome extension files resulting in the K Searches extension being added, and dropped Amadey payloads to C:\Users\admin\Pictures\Minor Policy\5RfuRxo3fpxiWkD42DRCixRe.exe and C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\J0KBFYBW\build2[1].exe.
PrivateLoader has been linked to broader cybercrime ecosystems rather than a single exclusive payload set. It has been described as powering or participating in pay-per-install services and has been used in campaigns tied to Water Orthrus/CopperPhish distribution, Glupteba delivery chains, Lumma infections, Socks5Systemz standalone deployment, and malware delivery via Discord CDN. High-confidence indicators directly mentioned in the content include the HTTP paths /api/tracemap.php and /api/firegate.php, the IPs 185.216.70.235 and 195.20.16.45, and a CopperPhish-chain PrivateLoader sample with SHA-256 48211c6f957c2ad024441be3fc32aecd7c317dfc92523b0a675c0cfec86ffdd9.
C2 tracking
Derp observations, rolling seven-day window
Samples
187979252bdf6e932753613b86202ce215132ccca8236215321c5c67b1de7875 3e68725df6872b5201f2462426b7b1b41aa8b3d7c1525b5be89f7e9d4032aac6 47ccf7af5db91cfd6774898fe25950ec95ac5a9cc44334603259b2c10bca7b8a cfecc2bc043b4b5e3d412bea8664227cb437b0deb1e75657a933e38492a8a1c8 dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9 dd1bf6486965d831246279c59076aa1606cd3a81926cb6ff314c3f4ed3184455 3c405151d59ea76d411aa6898792373cd563324fa3c19afd67f9a0236ab7358b 284ae9899ae53d03d27bd3f72892d843fe5bbecb097f52fc0b1b37d1040401d0 Reported operators
The campaign uses multiple malware families under a single operational umbrella: SHA256 (truncated) Filename Signature First Seen 95e30af4... PoisonX.exe PrivateLoader 2026-03-10
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.