DoiLoader
DOILoader, also referred to in the provided content as IDAT Loader or HijackLoader, is a malware loader used to execute encrypted follow-on payloads via DLL side-loading. In the observed activity, threat actors bundled trojanized DLLs with legitimate signed applications so that execution of the benign program side-loaded DOILoader, which then decrypted and launched the next-stage malware from an included encrypted file. Reported examples include a trojanized PYTHON27.DLL side-loaded by a renamed legitimate Ace Stream executable to execute an encrypted payload in Vos.xwtx and run zgRAT, and a trojanized DLL bundled with the signed application Rene.E Facebook Widget to load Lumma Stealer encoded in an m4a file. Proofpoint also described ClearFake activity in which a trojanized DLL using DOILoader loaded Lumma Stealer from an encrypted file extracted from a ZIP archive.
The malware is associated in the content with multiple financially motivated delivery clusters and campaigns. It was observed in malware chains tied to TA2727, where Windows users were typically served DOILoader and Lumma Stealer through fake browser update lures on compromised websites, with traffic routed by TA2726. It also appeared in broader activity sets that delivered XWorm, Amadey, zgRAT, NetSupport, and Lumma Stealer, including reservation-themed DanaBot-linked campaigns and Lovable-hosted malware delivery chains. Infection vectors directly mentioned include fake secure download pages, fake browser update pages, compromised websites with malicious injects, and archives containing legitimate executables plus trojanized DLL dependencies.
High-confidence indicators and artifacts directly mentioned in the content include the encrypted payload file Vos.xwtx, the trojanized PYTHON27.DLL, bundled m4a-encoded payload storage, and one command-and-control endpoint associated with a DOILoader-to-zgRAT chain: 84[.]32[.]41[.]163:7705.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The MSI installed and executed the legitimate and signed application “Rene.E Facebook Widget”. However, one of the bundled DLLs was trojanized with DOILoader, which was side loaded upon execution. DOILoader then ran Lumma Stealer, which was encoded in a bundled m4a file.
Techniques & procedures
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
Typically, an attack chain will consist of three parts: the malicious injects served to website visitors, which are often malicious JavaScript scripts; a traffic distribution service (TDS) responsible for determining what user gets which payload based on a variety of filtering options; and the ultimate payload that is downloaded by the script.
Execution
2 techniques
Execution
Stealth
1 technique
Stealth
Collection
1 technique
Collection
IOCs tracked for this family
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader embedded in a trojanized DLL and used to execute an encrypted payload that ultimately runs zgRAT.
Windows loader referenced as a payload delivered in TA2727 campaigns associated with Keitaro TDS traffic flows discussed alongside SocGholish delivery chains.
Referenced as another payload delivered by the same activity cluster that distributes DanaBot.
A loader delivered in the fake update chain via DLL side-loading from a trojanized bundled DLL. It executes secondary payloads including Lumma Stealer and DeerStealer.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.