Researchers linked PrivateLoader to a long-running pay-per-install malware ecosystem that used SEO-poisoned sites and cracked-software lures to infect Windows users with password-protected ZIP archives and NSIS installers. The loader was repeatedly observed delivering a wide range of payloads, including RedLine, Vidar, SmokeLoader, RisePro, Qbot, Dridex, DanaBot, TrickBot, Kronos, LockBit, STOP Djvu, and Conti, while related tooling such as Discoloader and the Go-based Anubis Loader expanded the same distribution chain. Investigations described administration panels used to manage payload links, browser extensions, bot installs, and operator activity, with one panel reportedly overseeing about 20,000 bots and collecting more than 11 GB of stealer logs in less than two weeks.
Separate reporting showed PrivateLoader also acting as an access broker for other criminal and state-linked operations. Analysts observed it distributing ColibriLoader in a campaign tied to UAC-0113, a group CERT-UA has associated with Sandworm, and later delivering Socks5Systemz, a proxy botnet that converted infected Windows hosts into rentable proxies. Bitsight estimated Socks5Systemz had about 10,000 infected systems and at least 53 servers supporting command-and-control, telemetry, DNS, and backconnect functions, with customers buying proxy access through a Telegram-linked service for cryptocurrency. Across the reporting, PrivateLoader emerged as a versatile initial-access platform connecting commodity stealers, banking trojans, ransomware, proxy monetization, and higher-end intrusion activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
20 events from the most recent confirmed update back to the earliest known activity.
A GitHub Gist published a Python script, privateloader_str_decrypt.py, that disassembles 32-bit PE files and recovers most PrivateLoader stack strings by reconstructing PXOR-based decryption routines. The tooling revealed new technical details about how analysts can extract obfuscated strings from PrivateLoader samples.
A GitHub Gist published a YARA rule named win_privateloader to detect PrivateLoader samples using PE characteristics, HTTP form content, geolocation-service references, hardcoded Chrome user-agent strings, and a repeated PXOR instruction pattern tied to string decryption. The rule metadata is dated 2024-01-11 and attributes the work to Bitsight.
Bitsight cited research indicating that PrivateLoader infected more than 1 million computers in 2023, averaging nearly 3,300 infections per day. The report also said recent indicators suggested the pace had risen to about 5,000 infections per day in 2024.
The ColibriLoader sample analyzed by Bitsight, which had been dropped by PrivateLoader, carried a date of September 4, 2022 and was later unpacked to its final executable stage.
Walmart Global Tech analyzed a PrivateLoader operation that used SmokeLoader tasking to deliver multiple payloads, including an IcedID loader communicating with deficulintersun.com. The same recovered task set also included Djvu ransomware, RedLine Stealer, a loader chain leading to Raccoon Stealer v2, and a CoinSurf installer.
Bitsight observed PrivateLoader distributing ColibriLoader samples in a campaign used by threat actor UAC-0113 between July and October 2022; CERT-UA had linked UAC-0113 to Sandworm.
Darktrace reported observing several PrivateLoader infections across multiple client environments between January and June 2022, describing a recurring chain in which users downloading cracked software were redirected to password-protected archives, often hosted via Discord CDN. The report detailed PrivateLoader's modular architecture, dead-drop resolver use, and follow-on payloads including Mars Stealer, SmokeLoader, RedLine, BeamWinHTTP, and crypto-miners.
In December 2021, the pab2 and pab3 affiliates recorded roughly 82,000 loads on the investigated delivery infrastructure.
Over a 20-day period in November 2021, the investigated PrivateLoader delivery infrastructure recorded more than 125,000 loads.
Researchers assessed that a single entity likely used the PrivateLoader PPI service to operate or distribute several banking trojan botnets, sometimes bundling stealers and ransomware such as LockBit and STOP Djvu.
PrivateLoader bots downloaded Dridex samples tied to botnet 10444, DanaBot samples with affiliate identifier 40, and Trickbot samples with gtags including lip*, tot*, and top*.
PrivateLoader bots in European countries were instructed to download the Kronos banking trojan from a specified URL, and the sample also executed the Vidar stealer.
A pab2 SmokeLoader sample downloaded by PrivateLoader delivered the Qbot banking trojan and exposed the new botnet ID star01.
Automated malware tracking for PrivateLoader began in early September 2021, enabling researchers to observe its payload distribution patterns and infrastructure.
ColibriLoader was first advertised as a malware-as-a-service offering on the XSS.is cybercrime forum, with pricing for weekly and monthly access and a bundled PHP control panel.
Researchers assessed that malware campaigns incorporated the PrivateLoader pay-per-install service since at least May 2021, using SEO-poisoned cracked-software sites to infect users.
Sekoia assessed with high confidence that PrivateLoader was the proprietary loader used by the ruzki pay-per-install operation, based on shared statistics URLs, overlapping infrastructure, actor activity, and botnet naming patterns. The report also tied ruzki to the aliases les0k and zhigalsz.
Bitsight identified a proxy botnet it named Socks5Systemz, delivered through the PrivateLoader and Amadey loaders and tied to a Telegram-based proxy sales operation.
Sekoia documented RisePro as a previously undocumented information stealer being distributed through PrivateLoader and detailed its credential, wallet, and file theft capabilities.
During their investigation, researchers observed additional loader traffic delivered by PrivateLoader and identified a separate Go-based malware family they named Anubis Loader.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
yaraify.abuse.ch
Open sourceblog.sekoia.io
Open sourceintel471.com
Open sourcede.darktrace.com
Open sourceblog.sekoia.io
Open sourcetavares.re
Open sourcezscaler.com
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.