Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

HijackLoader

35
Global rank
24 infographic chevron month
Month rank
34 infographic chevron week
Week rank
0
IOCs

HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses.

Loader
Type
Unknown
Origin
1 July, 2023
First seen
8 April, 2026
Last seen

How to analyze HijackLoader with ANY.RUN

Type
Unknown
Origin
1 July, 2023
First seen
8 April, 2026
Last seen

IOCs

IP addresses
91.199.163.124
179.43.166.242
193.233.112.188
213.165.45.183
66.90.86.58
179.43.139.10
87.121.79.21
141.255.161.122
91.84.123.231
154.213.177.2
45.156.87.17
77.110.118.195
92.255.85.108
45.59.124.94
167.17.40.170
77.91.101.66
166.88.62.248
147.124.219.109
62.60.234.80
194.120.116.197
Hashes
86bccbacd8e9fde23ff236155ee47f866dd7dd51c6129ed340034810a10705b3
bf933ccf86c55fc328e343b55dbf2e8ebd528e8a0a54f8f659cd0d4b4f261f26
0ae58be8d7058e40926fdb51b76043d109b96b91aa9fa2950dbb8a3626185e0f
a38da72082fc2dc1f60b3b245e1f2382d5f8c1d08ebc397dd0d81cc9f74ebbe6
8cc871ee8760a4658189528b4a5d8afe9824f6a13faaf1fe7eb56f2a3ad2d04e
8c12d821cae4d797fece228c0f433a007b8ad0643b778de8fa8a20b01504a522
aba5c1f30b8de1a07a4fcb401c55a07387f41994f9bb5495a604694b055b6f97
132e2aaf6ba22738d79a027f967b865154f427eb5aa9c623dd4a2e9c0656e279
c50bffbef786eb689358c63fc0585792d174c5e281499f12035afa1ce2ce19c8
d838c3ff4c5bc734ce3beb0101d2902731fe1f414eae611ecb427bb66d682f71
4ffb8d67aff441d7c75312221a715916941e29623e8c090dddd251a7e9a8d577
1495fe416d65a16ec29e30de2a8f410e2930278eacf43943c45804cc9f502b2f
4a35f8134f64ad28c5fe261d7cf15256ecd758566c2ddbf4bd962925502ade41
4416d271999879f69acf3f414d06ef47852c5a9f174a543b8d30784b10b6ce73
9469de22339cb061f83ad060ea6f2110c5f0c3c4a08017db2a5cf457691a83ca
7686ffb96c606f5138af8818871f433f6ebe6c94597e496da1c9b07b3c2338d4
5eec94a4cd6f1e0fa8a361ef8e78464431092718c4bda40ad5c83d607ef9a31c
038d7b257b98421ad371189cf51d67f32ddad2de687c443a59ea74e4027bbf04
9fcc8d9212ee92c395f48f4fc5e587431485426f1bfcf8f4640db7270ebcf18d
3c5ef21065ce78141738202ee7f678f8b1fe666d49b7639ff82f95eda73cdd2b
Domains
brokpolok.shop
cloudtflare.com
bowlina.cyou
playtogga.com
solstice-line-drift.pro
smgblicense.itopupdate.com
mullenpalimpseststudio.com
dl5e160728a1.pages.dev
fusionjanicepalimpsest.com
loque2025.mysynology.net
fortwaynejubileebrontide.com
effinghampodiatriclore.com
dl895b62d291.pages.dev
enviopago.mysynology.net
dckis13.duckdns.org
maximo26.duckdns.org
gestcular.cfd
pianepal.com
cosi.com.ar
downloadrufus.com
Last Seen at

Recent blog posts

post image
Building Phishing Detection That Works: 3 Ste...
watchers 434
comments 0
post image
ClickFix Meets AI: A Multi-Platform Attack Ta...
watchers 2475
comments 0
post image
From Reactive to Proactive: 5 Steps to SOC Ma...
watchers 4705
comments 0

What is HijackLoader malware?

HijackLoader is a loader malware that possesses strong evasion capabilities, allowing it to bypass mainstream security solutions. It has been observed to deliver numerous persistent malware families, such as DanaBot and the RedLine stealer.

Most of the known attacks involving HijackLoader began with phishing emails. As of the end of 2023, it continues to be an active threat. The modular design of the malware is one of the key factors behind its popularity. It enables HijackLoader to ensure a more flexible approach to deployment on the infected system and further execution of the final payloads.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Technical details of the HijackLoader malicious software

HijackLoader is notorious for its ability to evade detection. One way it does this is by utilizing a modified Windows C Runtime (CRT) function to gain a foothold on the device.

During the initial stage, HijackLoader also ascertains whether the final payload is embedded in the binary or has to be downloaded from external sources. It does this through the use of an array of DWORD values.

It can also check if the device is connected to the Internet by attempting to connect to legitimate websites. The network connectivity check is a clever strategy that allows HijackLoader to remain undetected while the network is unavailable. In a similar fashion, the malware can delay the execution of different parts of its code to once again avoid early detection.

To make it more difficult for reverse engineers to analyze its code, the malware uses dynamic API loading via a custom hashing method. This makes it harder to locate the specific API calls used during execution.

HijackLoader’s AVDATA module is designed specifically for the purpose of identifying security software installed on the system and adjusting its operation depending on the results of its scanning.

Execution process of HijackLoader

Let’s take a closer look at the execution flow of a HijackLoader sample by uploading it to the ANY.RUN sandbox.

HijackLoader is a typical loader, and its execution flow is also straightforward and simple. This simplicity allows malware to remain less active inside infected systems, making it more challenging to detect. However, it can still attract attention in certain cases.

In our example, the loader leveraged the CMD utility to stay under the radar. It, in turn, initiates the MSBuild process, which downloads and runs the Phonk which downloads the miner. HijackLoader demonstrates evasion capabilities that aid in staying undetected by certain security solutions.

Analyze malware for free in a fully interactive cloud sandbox – sign up now!

HijackLoader process tree shown in ANY.RUN HijackLoader's process tree demonstrated in ANY.RUN

Distribution methods of the HijackLoader malware

The preferred method of infiltration among the attackers behind HijackLoader is phishing attacks, where cybercriminals craft emails that appear to be from legitimate sources, hoping to trick recipients into opening malicious attachments or clicking on infected links.

In one notable instance, hotels were targeted with emails from fake clients claiming to be staying at the hotel and requesting staff to download a file containing information on their allergy. Once opened, the file kickstarted the infection chain resulting in the deployment of HijackLoader on the victim’s device.

Conclusion

Keeping your infrastructure safe from a HijackLoader infection requires a proactive cybersecurity approach. An indispensable part of it is a reliable malware analysis sandbox like ANY.RUN.

With ANY.RUN, you can example incoming emails to determine any malicious intent behind them with ease. The service’s interactive cloud environment enables you to effectively investigate even the most intricate phishing campaigns and uncover multi-stage attacks in no time. The service delivers comprehensive text reports encompassing detailed information about the submitted files and links, including fresh IOCs.

Adopt a proactive cybersecurity approach by leveraging ANY.RUN.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
DoubleTrouble screenshot
DoubleTrouble
doubletrouble
DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More
Socelars screenshot
Socelars
socelars
Socelars is an information-stealing Trojan (often categorized as spyware/stealer) that focuses on collecting sensitive data from Windows systems, with standout reporting around Facebook Ads Manager and session cookie theft. Unlike “noisy” malware that immediately breaks something, Socelars quietly converts a single infected machine into access: logged-in sessions, business account data, and pathways to monetization.
Read More