HijackLoader is a modular Windows malware loader first publicly reported in 2023 and designed to deploy secondary payloads while evading endpoint defenses. It has delivered information stealers and remote-access malware including Lumma Stealer, Vidar, StealC, DeerStealer, ACR Stealer, SilabRAT, and SnappyClient. It is distributed through ClickFix social-engineering lures, pirated or cracked software and game installers, malicious archives, and DLL side-loading chains; APT-C-36 has also used DLL side-loading to execute HijackLoader.
The loader uses encrypted configuration data and a module-based architecture supporting anti-virtual-machine checks, security-product discovery, system profiling, process injection, scheduled-task persistence, UAC bypass, Windows Defender interference, and reverse-shell functionality. Observed execution methods include DLL side-loading, module stomping, process doppelgänging or transacted hollowing, section mapping, thread-context hijacking, and self-hollowing. HijackLoader commonly resolves APIs by hash, obtains syscall information from clean system-library mappings, unhooks user-mode system libraries, and uses stack spoofing or indirect syscall mechanisms to obscure execution origins. Its final payload may be embedded in and decrypted from its configuration, or delivered through subsequent stages. HijackLoader targets Windows systems and is used as a flexible delivery framework rather than for a single fixed post-compromise objective.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT-C-36 has used side-loading to execute the HijackLoader payload.
The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.
The observed format is consistent with HijackLoader , also tracked as IDATLoader . The IDAT container is therefore not an isolated packer trick. It belongs to a wider modular loader framework that can deploy different components and final payloads depending on its configuration.
The infrastructure graph generated from the correlation of indicators identified in the campaign reveals a complex network of relationships... through this, we note similarities with the already well-known “HijackLoader.”
“...EncryptHub added to the game files the HijackLoader malware (CVKRUTNP.exe), which establishes persistence on the victim device and downloads the Vidar infostealer (v9d9d.exe).”
31 distinct techniques documented for this family, organized by ATT&CK tactic.
modTask Scheduled task persistence (32-bit); modTask64 Scheduled task persistence (64-bit).
This blob contained a second PowerShell script, decoded and immediately invoked... The third and final script is responsible for downloading and executing the MSI installer.
“Both the loader and HijackLoader build their syscall table the same way: read ntdll.dll from disk, walk the export directory, keep every export whose name begins with Zw, and pull the service number out of the function body.”
This module is responsible for dynamically loading another DLL from current directory named VSDebugScriptAgent170.dll using LoadLibraryA API.
The site... asked me to click it to prove I was human... instructions: press Win + R, then Ctrl + V, and finally Enter.
These include multi-stage infection chains involving heavily obfuscated and trojanized .NET DLLs; abuse of MSBuild, .csproj, and .bat files to execute them.
modTask Scheduled task persistence (32-bit); modTask64 Scheduled task persistence (64-bit).
Once the matching module is identified, it loads a system DLL to inject the shellcode.
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
With the payload mapped into the target process, execution needs to be diverted to it. This is done by modifying the context registers of a thread in the target process.
“The loader marks its own image writable, zeroes it and then calls into the function that is responsible for mapping the final payload in its place. From this point on the process is executing out of memory it has just erased.”
RenEngine Loader reads a .key file from disk, decodes its contents using Base64... locates an XOR-encoded archive... HijackLoader decompresses the data using the RtlDecompressBuffer API.
“The same API resolution order” and “a fresh copy of ntdll.dll is mapped from disk and a second batch of functions is resolved from it.”
The ad used a Google-themed verification prompt... presented what appeared to be a standard Google reCAPTCHA... storagesvc42.bak is not a standard file format. It mimics PNG’s IDAT chunk structure as a container for the encrypted payload.
Once the matching module is identified, it loads a system DLL to inject the shellcode.
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
With the payload mapped into the target process, execution needs to be diverted to it. This is done by modifying the context registers of a thread in the target process.
“The loader marks its own image writable, zeroes it and then calls into the function that is responsible for mapping the final payload in its place. From this point on the process is executing out of memory it has just erased.”
The loader then implements process doppelgänging, writing the shellcode extracted from the .tmp files into both ZoneInd.exe and chime.exe.
# Запуск и мгновенный выход Start-Process powershell -WindowStyle Hidden -ArgumentList "-NoProfile -ExecutionPolicy Bypass -File `" $tempScript `" " exit
It then extracts the archive's contents and executes a binary... Stomped Evr.dll reads an encrypted file... compressed module data [is] unpacked.
Start-Process "msiexec.exe" -ArgumentList "/i `" $filePath `" /qn /norestart" -Wait -WindowStyle Hidden
Execution then enters an anti-analysis routine... checks including RDTSC timing, CPUID vendor fingerprinting, RAM size, CPU count, and hostname inspection.
The loader calculates a scoring sum... to identify if the current execution is within a sandbox machine... If this percentage is below 50, the loader proceeds with execution; otherwise, it terminates silently.
bundling a legitimate application alongside two tampered DLLs... malicious code had been stomped directly into the DLL’s legitimate exports.
The MSI installer turned out to be a carefully constructed package, bundling a legitimate application alongside two tampered DLLs. These facilitated the loading of HijackLoader...
RAM... Hard Disk Storage... CPU Cores... Device Serial... Device Model... Device Manufacturer
Execution then enters an anti-analysis routine... checks including RDTSC timing, CPUID vendor fingerprinting, RAM size, CPU count, and hostname inspection.
221 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
76 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader mentioned solely as a comparison for its use of module stomping in a separate campaign.
A loader mentioned only as a comparison for DLL/module stomping behavior in a separate campaign.
Named as an alternative payload delivered in some PavinLoader infections, indicating the loader can flexibly deploy different malware.
An additional loader observed as a secondary payload in some PavinLoader infections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.