Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

PrivateLoader

127
Global rank
110 infographic chevron month
Month rank
118 infographic chevron week
Week rank
0
IOCs

PrivateLoader is a malware family that is specifically created to infect computer systems and drop additional malicious programs. It operates using a pay-per-install business model, which means that the individuals behind it are paid for each instance of successful deployment of different types of harmful programs, including trojans, stealers, and other ransomware.

Loader
Type
ex-USSR
Origin
1 May, 2021
First seen
27 August, 2026
Last seen

How to analyze PrivateLoader with ANY.RUN

Type
ex-USSR
Origin
1 May, 2021
First seen
27 August, 2026
Last seen

IOCs

IP addresses
172.211.123.250
74.178.240.61
23.52.181.141
94.142.138.113
48.209.6.48
40.126.32.76
149.154.158.34
128.24.231.65
88.221.169.152
48.209.138.168
208.67.104.60
94.142.138.131
48.209.133.15
2.16.164.120
135.232.92.97
172.178.240.161
23.59.18.102
40.126.31.1
135.233.95.144
95.100.102.9
Hashes
b57a88e5b1acf3a784be88b87fa3ee1f0991cb7c1c66da423f3595ffc6e0c5c2
44ee2445a8afa4123bd2edb2bcbe258f8c344f73fda88d03097e22a7928d313d
e771e53116599a93d67d904f1e067452d89e75a9fe032bf35879befce7e55c0e
b2549a6f78c10f7561710d06a9dd3f825f853f0afa20bda1eb37cc7d0b7192a4
f2b942af74f8846ba3b6141c845b368ac8a1eea9cae2226414a735ee920774e4
87a9323ac85ce28867d5d7ce590c8f29b8d1a999961fca71bb33adef48683691
49cf6cb3c16ca60802ade5f101e562c9f633fef3c2d5456fbf0e147da85a39e6
7e07d936cc4abb9852b0d0939710aee165f8e6f6561f222eb96d0093975e91a1
fcd980fba47af8df80f46201b42453d48e9092535c0b213caebc6091fe525394
c1a5388596c4a93424013011fd7dd4b2b8ad60f6f4a5d12a3f340a360010180a
31440a0f15ff9be959d80656850d9ca9e8ff08ec2a26ac9a5041238bc0f8734e
233d9337ba70308d32060f8f40de8d602cb6092116266ab0a0d73e2fc7f137b5
d0dac0f0606b2fc19789a4ae3672869067574387a977685b7a512fbe6aa6c9dc
6258f25b1100a1862ab7cbb652f48705bd7d7b873dc7611915d4aba37fd425a6
ed80808baa7532e355e31f820968e7541a33965b5b794b1628d24305e21536b3
08e0d2c2fbe0f9eae73f152295ee2b907c34240db8ed5dce55e3948e172763ad
02aecba6c26476eb069cd6d72c26b51a2608c9152fc0ab89883f9060b78dbd6b
ad12975fa8efa47b78ef6f2aaa0e834454d8e93a695dba8fd92ae3ff8cef521d
254c86e7ffdf4eccebdf1cfb2d0e54507f1aab03acbcf0c6c106bdd3e49ce2de
a0a0d67efdf5241e459a9f70baa540aea951be40c59ff37d984c42bcb0c76ab4
Domains
activation-v2.sls.microsoft.com
settings-win.data.microsoft.com
login.live.com
fe3cr.delivery.mp.microsoft.com
www.microsoft.com
google.com
go.microsoft.com
slscr.update.microsoft.com
client.wns.windows.com
crl.microsoft.com
watson.events.data.microsoft.com
ocsp.digicert.com
cxcs.microsoft.net
www.bing.com
oneocsp.microsoft.com
ocsp.digicert.cn
avatars.githubusercontent.com
raw.githubusercontent.com
edge.microsoft.com
user-images.githubusercontent.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://94.142.138.113/api/tracemap.php
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.2.crl
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.1.crl
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.3.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2191
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6596
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10054
comments 0

What is PrivateLoader malware?

PrivateLoader is a loader, which serves to embed other malware families on compromised systems. The creators of this malicious software, who are likely to be from ex-USSR countries, monetize their activity by charging various threat actors for the installation of their particular type of payload. The services are advertised openly on forums and Telegram channels, making them widely accessible.

The earliest instances of the malware’s activity can be traced to the beginning of 2021. However, researchers were able to spot it for the first time only in 2022, when it gained notoriety as the most widely used loader of the year.

A common vector of infection in the case of PrivateLoader has been through websites offering cracked versions of popular software. Once victims downloaded a file from such sites and ran an alleged software executable, they launched a chain reaction, which led to the installation of PrivateLoader and eventually to a trojan, stealer, or another type of malware being deployed on their system.

Some of the known malware families that have been pushed by PrivateLoader include Redline, DCRAT, Raccoon, and Smokeloader.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Technical details of the PrivateLoader malicious software

PrivateLoader is written in C++ and has a control panel, allowing operators to manage its activity, including by adding new payload links and tracking the total number of installations.

PrivateLoader is set up to drop payloads depending on the configuration of each victim’s system. For instance, it can distribute malware based on the geo location. It can also scan the machine to determine if there are any crypto wallets installed and see banking credentials. Yet, in most cases, it does not exfiltrate this information.

PrivateLoader is a modular threat, consisting of three distinct parts, each with its own purpose. It starts with the Loader module, which is intended for downloading the main Core module. The latter then contacts the command-and-control server (C2) and drops the next-stage threat, as well as the Service module that is regularly updated and responsible for keeping the loader on the victim’s system. In certain instances, PrivateLoader can drop several payloads.

The malware also makes use of the Dead Drop Resolver technique, where it utilizes legitimate services, such as Discord, to host malicious payloads.

PrivateLoader employs various techniques to prevent analysis, including encrypting its important strings and obfuscating the C2 communication.

Execution process of PrivateLoader

Let’s see how PrivateLoader operates in detail by uploading its sample to ANY.RUN, an interactive sandbox for malware analysis.

The main PrivateLoader process creates a child process whose executable file is located in the user’s “Pictures” directory. The created child process is added to the startup using Task Scheduler. The executable file of the child process was downloaded from the Internet.

Analyzing the HTTP requests, we can observe connections and data exchanges with the C2 server. The content sent (as well as received) in POST requests consists of BASE64-encoded strings. Moving forward to the indicators, we can see that the malware steals user credentials from browsers.

Read a detailed analysis of PrivateLoader in our blog.

PrivateLoader process tree shown in ANY.RUN PrivateLoader’s process tree demonstrated in ANY.RUN

Distribution methods of the PrivateLoader malware

As mentioned above, the primary way PrivateLoader can infect a computer is via a direct download. Attackers employ SEO poisoning to boost the ranking of their websites. Users visit these links in search of different types of legitimate programs. Yet, after downloading an archive from the website and opening its contents, an infection begins, allowing PrivateLoader to compromise the entire system.

Conclusion

PrivateLoader is a serious threat to organizations and individuals because of the scale of its operation, as it can infect hundreds of thousands of computers in a short period of time. In order to avoid falling victim to this and other malware, it is vital to steer clear of suspicious websites and never download software from unofficial sources.

To determine whether a certain file or link is malicious, use ANY.RUN. It is a malware sandbox that provides users with the ability to interact with the samples at hand in a safe cloud environment. For instance, PrivateLoader usually comes packed into a passworded archive. ANY.RUN lets you easily open it, extract the contents, and run them as if you were using your own computer to expose any harmful behavior and collect IOCs.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

Remus Stealer screenshot
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
Read More
Diamotrix screenshot
Diamotrix
diamotrix
Diamotrix is a stealthy cryptocurrency clipper malware that silently monitors the Windows clipboard, waiting for the moment a user copies a digital wallet address. Diamotrix replaces it with an attacker-controlled wallet, invisibly redirecting any resulting transaction. Because blockchain transfers are irreversible, victims rarely discover the theft until the funds are long gone.
Read More
Keylogger screenshot
Keylogger
keylogger
A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.
Read More
DonutLoader screenshot
DonutLoader
donutloader donut
DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.
Read More
Cerber screenshot
Cerber
cerber
Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.
Read More
Tykit screenshot
Tykit
tykit
Tykit is a sophisticated phishing-as-a-service (PhaaS) kit that emerged in May 2025, designed to steal Microsoft 365 corporate credentials through an innovative attack vector: malicious SVG files.
Read More