Cybersecurity experts recently examined the complex workings of an extremely insidious loader known as “in2al5d p3in4er,” which is used to spread the Aurora data-stealing malware.
“The in2al5d p3in4er loader is compiled with Embarcadero RAD Studio and targets workstations using advanced anti-VM (virtual machine) techniques,” cybersecurity firm Morphisec said in a report shared with The Hacker News.
Aurora, an information thief built with the Go programming language, debuted on the threat landscape in late 2022. It is marketed to other malicious actors via YouTube videos and fake cracked software download sites that are optimized for search engines .
By simply following links included in YouTube video descriptions, unsuspecting victims can be taken to malicious websites, where they are tricked into downloading malware disguised as legitimate software.
Morphisec tested a loader that checks the vendor ID of the graphics card installed on any system and compares it to an approved list with AMD, Intel , or NVIDIA as viable options. If there is no match between these two values, then the loader will automatically terminate its operations.
After decrypting the last packet, the loader injects it into a genuine process named “sihost.exe” through a tactic called process hollowing. Alternatively, some loader examples also allocate memory for the composition of the decrypted payload and launch it from there.

Leveraging Embarcadero RAD Studio, the loader is designed to create executables that can be used on multiple platforms. This ensures that it remains undetectable and able to perform its malicious functions stealthily.
In short, the research reveals that the in2al5d p3in4er malicious actors are using social engineering tactics for an extensive campaign that uses YouTube as a malware distribution platform and redirects viewers to convincing websites that resemble fraudulent websites for distributing stealer malware.
Intel 471 recently uncovered AresLoader, a malware loader that is offered as a service to criminals for as little as $300/month. The malware can disguise itself as legitimate programs through the use of a binder tool and appears to originate from an organization linked to Russian hacktivism. This development reveals yet another danger posed by increasingly sophisticated cybercriminals.
Since January 2023, AresLoader has been used to spread several notorious malware families, including Aurora Stealer, Laplas Clipper, Lumma Stealer, Stealc, and SystemBC.
Information source: thehackernews.com
