A new version of the malware loader, HijackLoader, features more robust anti-analysis techniques to avoid detection.

“These improvements aim to enhance the stealth of the malware, thus remaining undetected for longer periods of time,” said Zscaler ThreatLabz researcher Muhammed Irfan V A.
According to the researcher, Hijack Loader now has features to evade Windows Defender Antivirus, bypass User Account Control (UAC), and avoid inline API hooking often used by security.
See also: Cuttlefish Malware: Hacks routers for covert surveillance
HijackLoader is also known as IDAT Loader and loads additional malware onto a compromised system. It was first reported by cybersecurity Zscaler in September 2023. Since then, it has been used to distribute various malware, including Amadey, Lumma Stealer, Meta Stealer, Racoon Stealer V2, Remcos RAT, and Rhadamanthys.
What makes the latest version more special is that it decrypts and parses a PNG image to load the next-stage malicious payload. The malware loader has a first stage, which is responsible for extracting and launching the second payload from the PNG, which is either embedded in it or downloaded separately based on the malware's configuration.
“The main purpose of the second stage is to introduce the main instrumentation module,” Irfan explained. “To increase stealth, the second stage uses more anti-analysis techniques using multiple modules.
See also: New Latrodectus malware attacks exploit Microsoft themes
“Amadey was the malware most frequently delivered via HijackLoader,” Irfan said. “The second stage loading involves the use of an embedded PNG or a PNG image downloaded from the internet. Additionally, new modules have been integrated into HijackLoader, enhancing its capabilities and making it even more powerful.

One of the key ways to prevent a HijackLoader attack is to use up-to-date software . Malicious users often exploit vulnerabilities in old software versions to infiltrate systems. Therefore, it is important to check and update your software on a regular basis.
Another important preventive measure is to be careful when opening emails and attachments. Avoid opening messages from unknown senders or with suspicious content. Also, do not click on attachments that you were not expecting or that look suspicious.
See also: ZLoader malware: Adopts anti-analysis strategies from Zeus Banking Trojan
Additionally, using strong passwords is crucial to protect against the HijackLoader malware loader. Choose long and complex passwords that include letters, numbers, and special characters. Avoid reusing your passwords across different services.
Finally, installing and updating reliable security software is essential for protection against malware. A good security program can detect and isolate malware before it can cause damage to your system.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
