The perpetrators behind a malicious loader program called HijackLoaderhave added new techniques to evade detection as the malware continues to be increasingly used by other perpetrators to deliver additional payloads and tools.
See also: HijackLoader modular malware loader has become very popular with hackers

HijackLoader was first recorded by Zscaler ThreatLabz in September 2023 as a means of delivering DanaBot, SystemBC, and RedLine Stealer. It is also known to share a high degree of similarity with another loader, known as IDAT Loader.
Both loaders are believed to be operated by the same cybercriminal. In the intervening months, HijackLoader has been spread via ClearFake and used by TA544 (also known as Narwhal Spider, Gold Essex, and the Ursnif Gang) to deliver the Remcos RAT and SystemBC via search messages.
The initial moment of the multi - stage attack chain is an executable file (“ streaming_client.exe ”) that checks for an active internet connection and proceeds to download a second-stage configuration from a remote server .
The executable then loads a legitimate dynamic-link library (DLL) specified in the configuration to activate the shellcode responsible for launching the HijackLoader payload through a combined use of process doppelgänging and process hollowing that increase analysis complexity and evasion capabilities.
See also: MGM Resorts: Important systems out of service due to "cybersecurity incident"

Heaven's Gate refers to a deception trick that allows malware to evade endpoint security products by invoking 64-bit code in 32-bit processes on Windows, effectively bypassing user-mode hooks.
One of the main evasion methods observed in the following HijackLoader serial patches is the use of a process injection mechanism called “ transacted hollowing ”, which has been previously observed in malware such as the Osiris banking trojan
See also: Sponsor malware: Iranian hackers use backdoor in 34 organizations
How does Loader Malware work?
Loader Malware is a type of malware that is used to load and execute other malicious software on a system without the user's knowledge or consent. Loader Malware typically enters a system by exploiting vulnerabilities, using phishing , or by downloading files that appear harmless but contain malicious code. Once installed, Loader Malware begins downloading and executing other malicious software, such as trojans, ransomware, or spyware, by exploiting the system's vulnerabilities.
Loader Malware can also create a backdoor in the system, allowing attackers to gain access and control the system remotely. To combat Loader Malware, it is important to keep your software and operating system up to date, use strong security software, and be careful about the files you download and the links you click on.
Source: thehackernews
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
