PrivateLoader is a Windows malware loader and pay-per-install distribution service active since early 2021. Its primary role is to download and execute additional malware for multiple threat actors, and it has been used to deliver a broad range of commodity crimeware including information stealers, banking trojans, remote access trojans, proxy bot malware, cryptominers, spambots, and ransomware such as STOP/DJVU. The family is commonly associated with malware delivery ecosystems built around cracked or pirated software, where victims are lured through SEO-poisoned or software-download sites and receive password-protected archives or installer packages that ultimately launch the loader.
PrivateLoader is modular, with loader, core, and service functionality observed across variants. It retrieves command-and-control information through resolver mechanisms, downloads encrypted second-stage components, decrypts and injects them into memory, and then obtains payloads or tasking from its infrastructure. The malware supports selective payload delivery based on victim attributes such as geography, installed software, financial or cryptocurrency-related activity, and aspects of the host environment. Observed command sets include retrieval of payload links and browser-extension payloads, campaign tracking, and execution telemetry. Anti-analysis and obfuscation are prominent, including encrypted strings, dynamic API resolution, junk code, and packed samples.
Beyond simple payload staging, PrivateLoader has shown persistence and defense-evasion behavior. Reported variants create scheduled tasks, self-update, reinstall loader components, and in some cases disable or weaken Microsoft Defender. It also performs host and software discovery to guide downstream payload selection. PrivateLoader has been linked to large-scale global infection activity and has been observed distributing families such as RedLine, Vidar, SmokeLoader, RisePro, Amadey, IcedID, Tofsee, Socks5Systemz, NetDooka, and STOP/DJVU. It is used by multiple financially motivated actors rather than a single exclusive operator, making it a significant malware-as-a-service delivery platform in the cybercrime ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
PrivateLoader is a loader from a pay-per-install malware distribution service that has been utilized to distribute info stealers, banking trojans, loaders, spambots, rats, miners and ransomware on Windows machines.
PrivateLoader is one of the most widely used loaders in 2022. It is used by a Pay-Per-Install service to deploy multiple malicious payloads on the infected hosts. First observed in May 2021, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
PrivateLoader was seen being distributed through SEO-optimized websites that claim to provide cracked software. Victims download a password-protected zip file (the password is in the file name) which contains an NSIS installer that executes many malicious payloads, including PrivateLoader.
The service module takes care of persistence by creating a scheduled task
Some samples are not being detected because they are packed and this rule will only work on unpacked samples or in memory dumps, for the more recent versions.
This file is responsible for setting up the persistence and injecting the proxy bot in memory.
System checks before starting the malware symphony ... T1016: System Network Configuration Discovery
the customers of the service are able to selectively deliver malware to victims based on location, financial activity, environment, and specific software installed
the malware has additional capabilities, such as disabling Windows Defender, the discovery of user-sensitive data, and many anti-analysis techniques
Process 4440 is also seen communicating with its C2 server, 185[.]216.70.235 and 195.20.16[.]45 via port 80 (T1071 – Application Layer Protocol).
it will output most of the encrypted strings, more than 1500, including the current PrivateLoader C2 IP addresses at the time of writing of this blog post
These domains are simply proxies but behind them sits a massive operation performing millions of loads for various customers.
In the first stage, the loader is executed, which downloads and executes the second stage, the core module. The core module's primary purpose is to download and execute more malware, including another PrivateLoader module named service.
859 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pay-per-install loader used to deliver additional malware.
Referenced only in appendix literature as malware associated with the rise of a proxy service.
Named as a loader previously tracked in the same commodity malware delivery ecosystem.
A loader used to distribute Socks5Systemz as a standalone final payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.