Hackers lure unsuspecting users with free or pirated versions of commercial software into delivering a malware loader called Hijack Loader, which in turn deploys an information stealer known as Vidar Stealer.

"Hackers were able to trick users into downloading password-protected archive files, which contained trojanized copies of a Cisco Webex Meetings application (ptService.exe)," Trellix security researcher Ale Houspanossian said in an analysis on Monday.
See also: Grandoreiro trojan targets Brazil again – Pakistan receives smishing attacks
“When unsuspecting victims extracted and executed a binary file called “Setup.exe,” the Cisco Webex Meetings secretly loaded a stealth malware loader, leading to the execution of an information-stealing module.”
The starting point of the attack is a RAR archive file containing an executable file named “Setup.exe”, which is actually a copy of the Cisco Webex Meetings ptService module. What makes the campaign notable is the use of DLL sideloading techniques to secretly launch the Hijack Loader (also known as DOILoader or IDAT Loader). This acts as a conduit for delivering the Vidar Stealer via an AutoIt script.
“The malware uses a known technique to bypass User Account Control (UAC) and exploit the CMSTPLUA COM interface to escalate privileges,” Houspanossian added. “Once privilege escalation is achieved, the malware is added to the Windows Defender to avoid detection.”
The attack, in addition to using Vidar Stealer to obtain sensitive credentials from web browsers, leverages additional payloads to deploy a cryptocurrency on the compromised computer.
The revelation follows a surge in ClearFake campaigns, in which website visitors are lured into manually running a PowerShell script to fix a supposed web page display issue. This technique was previously uncovered by ReliaQuest late last month.
The PowerShell script then acts as a launchpad for the Hijack Loader, which ultimately installs the Lumma Stealer malware. The stealer is equipped to deliver three additional payloads, including the Amadey Loader, a downloader that launches the XMRig miner, and a clipper malware to redirect crypto transactions to wallets controlled by the attackers.
Read more: North Korean hackers target Brazil
“Proofpoint researchers Tommy Madjar, Dusty Miller, and Selena Larson observed that Amadey was also downloading other malware, such as JaskaGO, a Go-based program. Also in mid-April 2024, the security detected another cluster of activity, ClickFix, which used fake browser updates to visitors of compromised websites to spread Vidar Stealer, through a mechanism that involved copying and executing PowerShell code.
Another threat actor, TA571, has adopted similar social engineering in its malicious email campaigns. It sends emails with HTML attachments that, when opened, display an error message: “The 'Word Online' extension is not installed in your browser.” The message includes two options, “How to fix it” and “Automatic fix.” If the victim selects the first option, a Base64-encoded PowerShell command is copied to the clipboard and instructions are provided to run the code. In the case of “Automatic fix,” “fix.msi” or “fix.vbs” files are displayed that exploit the “search-ms:” protocol. Executing these files results in the installation of Matanbuchus or DarkGate.
See also: DarkGate malware exploits Microsoft flaw
Other variations of the campaign have led to the distribution of the NetSupport RAT, demonstrating the continued efforts to modify and update attack methods, despite the need for significant user interaction .“The legitimate use and multiple ways of storing the malicious code, as well as manual execution by the victim, make these threats difficult to detect,” Proofpoint said. “As antivirus software and EDRs have difficulty inspecting clipboard content, detection and blocking must occur before the malicious HTML/website is presented to the victim.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Meanwhile, eSentire uncovered a malware that uses Indeed[.]com-impersonating websites to distribute the SolarMarker malware via a decoy document purporting to offer team building ideas. “SolarMarker uses SEO poisoning techniques to manipulate search results and increase the visibility of deceptive links,” the Canadian cybersecurity firm said.
Read more: New malware targets exposed Docker APIs for cryptocurrency mining
“The use of SEO tactics by hackers to direct users to malicious websites highlights the importance of being careful about clicking on search results, even if they appear legitimate.”
Source: thehackernews
