HijackLoader — Malware Profile

HijackLoader is a modular Windows loader first observed in July 2023 that stages and delivers second-stage payloads rather than acting on objectives itself; Elastic Security Labs tracks the same family as GHOSTPULSE and Rapid7 named it IDAT Loader. It chains multiple defense-evasion techniques, among them DLL search order hijacking, process doppelganging built on NTFS transactions, module stomping, unhooking ntdll by remapping a clean copy read from disk, and Heaven's Gate to execute NTDLL APIs. Early versions hid encrypted payloads in the IDAT chunk of PNG files, the trait behind Rapid7's naming, while later samples instead recover an encrypted configuration from an image's pixel RGB values read through GDI+. Documented delivery includes the ClearFake fake-browser-update lure reported by Rapid7 and code-signed MSIX installers impersonating Chrome, Brave, Edge and WebEx reported by Elastic, with observed final payloads including Lumma Stealer, StealC, Amadey, Rhadamanthys, Vidar, SectopRAT and NetSupport.

IntelFusions coverage

Read the full analysis on IntelFusions