Rugmi is a Windows malware loader tracked by some vendors as HijackLoader and IDAT Loader. It operates as a malware-as-a-service and pay-per-install delivery mechanism used by financially motivated threat actors to deploy a wide range of follow-on payloads, especially information stealers. Reported payloads delivered through Rugmi include Aurora Stealer, Lumma Stealer, Vidar, RecordBreaker, Rescoms, Rhadamanthys, DanaBot, CryptBot, and SectopRAT.
Rugmi has been described as comprising multiple component types: a downloader that retrieves an encrypted payload, a loader that executes a payload from embedded internal resources, and a loader that runs a payload from an external file stored on disk. Observed variants use layered execution chains, encrypted or compressed containers, dynamic API resolution, and aggressive defense-evasion techniques. Delivery and execution commonly rely on DLL sideloading and search-order hijacking with legitimate signed binaries, including multi-stage sideloading chains that launch malicious DLLs through trusted executables. Additional observed behaviors include Living-off-the-Land execution via native Windows utilities, process injection into explorer.exe, possible UAC bypass support, scheduled-task creation, and persistence through user startup mechanisms and copied binaries in user-profile locations.
Rugmi is closely associated with commodity malware ecosystems and affiliate-driven distribution operations. It has appeared both as a payload distributed by other loaders such as Amadey and as an initial execution mechanism for downstream stealers such as Lumma Stealer and DeerStealer. Campaigns linked to the Rugmi ecosystem have used social-engineering lures, including fake software and password-management themed decoys, and at least some activity has been associated with malvertising-driven delivery chains. Related reporting also notes targeting of Ukrainian organizations in some IDAT Loader campaigns.
The malware primarily targets Windows systems and serves as an adaptable staging platform for post-compromise payload delivery. Its role in the intrusion lifecycle is to establish execution, evade detection, persist long enough to complete staging, and hand off control to credential theft, session theft, surveillance, or broader post-exploitation malware selected by affiliates or customers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"Our analysis shows that LummaStealer infections are primarily driven by social engineering rather than by the exploitation of technical vulnerabilities. Malware campaigns consistently rely on users unwittingly running infected files, using simple lures such as fake cracked software, fake games or media downloads, and abuse of trusted platforms."
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rugmi is mentioned as a payload distributed by a large botnet cluster within the Amadey ecosystem.
Rugmi is referenced as the loader ecosystem used by the affiliate to deliver DeerStealer through malvertising and deceptive software installers.
Referenced only as part of related infrastructure in the broader cluster; the content does not provide further malware functionality details.
A MaaS/pay-per-install loader ecosystem that uses DLL sideloading, LoTL via MSBuild.exe, persistence through the Startup folder, process injection, and staged payload delivery. In this sample it delivers Aurora Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.