Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

PrivateLoader

129
Global rank
131 infographic chevron month
Month rank
148 infographic chevron week
Week rank
0
IOCs

PrivateLoader is a malware family that is specifically created to infect computer systems and drop additional malicious programs. It operates using a pay-per-install business model, which means that the individuals behind it are paid for each instance of successful deployment of different types of harmful programs, including trojans, stealers, and other ransomware.

Loader
Type
ex-USSR
Origin
1 May, 2021
First seen
8 September, 2026
Last seen

How to analyze PrivateLoader with ANY.RUN

Type
ex-USSR
Origin
1 May, 2021
First seen
8 September, 2026
Last seen

IOCs

IP addresses
23.52.181.141
48.209.138.168
34.117.59.81
23.59.18.102
104.26.4.15
23.48.23.177
74.178.240.51
142.251.127.94
208.67.104.60
163.123.143.4
93.186.225.194
2.16.204.156
23.254.227.214
40.126.31.3
23.254.227.205
48.192.1.64
104.17.27.25
48.209.138.189
23.254.227.202
23.11.41.157
Hashes
27c1ed01c767f504642801a7e7a7de8d87dbc87dee88fbc5f6adb99f069afde4
cc0b4e42510d49c6decd464123ecf3b14ae9b47f9b4ed2ee64893e2d6520a264
58d44fa4beedd1bc81d43eb0d7e2c9273ea1c50e4f91b76e097859fea1991a42
9550b5a53a275eda024cd6be867b0a3e4572e2e76ec5f230853c90b438d92fb4
ee024d623ec98263950983a88f74f5e364d8876c3a16d346e34d6aaceb420325
b57a88e5b1acf3a784be88b87fa3ee1f0991cb7c1c66da423f3595ffc6e0c5c2
9013c7db91cfd7c9afb5b6eca80f900e5fcd59c8f69fb175f7c804eef476b742
55f6a88dc02579e8f6f191ee9ec91f66067b5d362434877cfbc325e4bf23aef1
2f3bf1110899a66d69eed2c93cb7df127d062a1251bf1f8b8589a23f6c12f00b
b2549a6f78c10f7561710d06a9dd3f825f853f0afa20bda1eb37cc7d0b7192a4
f2b942af74f8846ba3b6141c845b368ac8a1eea9cae2226414a735ee920774e4
a6f8f5d4ffd1e825ffce9a55861f16aa4dbe67871b1696b976194dd8be1fdf29
c14d3913451eaaccc04743d2b84c7e1ec8edd9038821dae912e404fcb24aa498
0ecc589dcc7796055b313e77a838a950f9eab4648ccceae06ee16db2f05fa5b0
a1617d0a1566ec8872c0aae57b113882e8b52f911857f22dc667e0502f0f61df
e30eb3e1c4ba36e9d5b21246ad508cbe21357bcb92f6bf32fafbbb21f7aad0bc
bd7a6ff344ceeeae3ea54acd52e982356df30f7e20c691a291ab4ae94b0eb734
44ee2445a8afa4123bd2edb2bcbe258f8c344f73fda88d03097e22a7928d313d
87a9323ac85ce28867d5d7ce590c8f29b8d1a999961fca71bb33adef48683691
cac92dd21b1fef2ec098dfa068b01043874f7a41ab169e40526f5bb3c71cfa1e
Domains
activation-v2.sls.microsoft.com
login.live.com
fe3cr.delivery.mp.microsoft.com
api.db-ip.com
settings-win.data.microsoft.com
crl.microsoft.com
google.com
www.microsoft.com
c.pki.goog
self.events.data.microsoft.com
go.microsoft.com
ocsp.digicert.com
slscr.update.microsoft.com
vk.com
www.maxmind.com
db-ip.com
ipinfo.io
dns.msftncsi.com
ecs.office.com
client.wns.windows.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://23.254.227.214/api/tracemap.php
http://23.254.227.202/api/tracemap.php
http://23.254.227.205/api/tracemap.php
https://ipinfo.io/widget
https://db-ip.com/
https://api.db-ip.com/v2/p31e4d59ee6ad1a0b5cc80695a873e43a8fbca06/self
http://www.maxmind.com/geoip/v2.1/city/me
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
http://c.pki.goog/r/r1.crl
Last Seen at
Last Seen at

Recent blog posts

post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 1613
comments 0
post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 3443
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 6576
comments 0

What is PrivateLoader malware?

PrivateLoader is a loader, which serves to embed other malware families on compromised systems. The creators of this malicious software, who are likely to be from ex-USSR countries, monetize their activity by charging various threat actors for the installation of their particular type of payload. The services are advertised openly on forums and Telegram channels, making them widely accessible.

The earliest instances of the malware’s activity can be traced to the beginning of 2021. However, researchers were able to spot it for the first time only in 2022, when it gained notoriety as the most widely used loader of the year.

A common vector of infection in the case of PrivateLoader has been through websites offering cracked versions of popular software. Once victims downloaded a file from such sites and ran an alleged software executable, they launched a chain reaction, which led to the installation of PrivateLoader and eventually to a trojan, stealer, or another type of malware being deployed on their system.

Some of the known malware families that have been pushed by PrivateLoader include Redline, DCRAT, Raccoon, and Smokeloader.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Technical details of the PrivateLoader malicious software

PrivateLoader is written in C++ and has a control panel, allowing operators to manage its activity, including by adding new payload links and tracking the total number of installations.

PrivateLoader is set up to drop payloads depending on the configuration of each victim’s system. For instance, it can distribute malware based on the geo location. It can also scan the machine to determine if there are any crypto wallets installed and see banking credentials. Yet, in most cases, it does not exfiltrate this information.

PrivateLoader is a modular threat, consisting of three distinct parts, each with its own purpose. It starts with the Loader module, which is intended for downloading the main Core module. The latter then contacts the command-and-control server (C2) and drops the next-stage threat, as well as the Service module that is regularly updated and responsible for keeping the loader on the victim’s system. In certain instances, PrivateLoader can drop several payloads.

The malware also makes use of the Dead Drop Resolver technique, where it utilizes legitimate services, such as Discord, to host malicious payloads.

PrivateLoader employs various techniques to prevent analysis, including encrypting its important strings and obfuscating the C2 communication.

Execution process of PrivateLoader

Let’s see how PrivateLoader operates in detail by uploading its sample to ANY.RUN, an interactive sandbox for malware analysis.

The main PrivateLoader process creates a child process whose executable file is located in the user’s “Pictures” directory. The created child process is added to the startup using Task Scheduler. The executable file of the child process was downloaded from the Internet.

Analyzing the HTTP requests, we can observe connections and data exchanges with the C2 server. The content sent (as well as received) in POST requests consists of BASE64-encoded strings. Moving forward to the indicators, we can see that the malware steals user credentials from browsers.

Read a detailed analysis of PrivateLoader in our blog.

PrivateLoader process tree shown in ANY.RUN PrivateLoader’s process tree demonstrated in ANY.RUN

Distribution methods of the PrivateLoader malware

As mentioned above, the primary way PrivateLoader can infect a computer is via a direct download. Attackers employ SEO poisoning to boost the ranking of their websites. Users visit these links in search of different types of legitimate programs. Yet, after downloading an archive from the website and opening its contents, an infection begins, allowing PrivateLoader to compromise the entire system.

Conclusion

PrivateLoader is a serious threat to organizations and individuals because of the scale of its operation, as it can infect hundreds of thousands of computers in a short period of time. In order to avoid falling victim to this and other malware, it is vital to steer clear of suspicious websites and never download software from unofficial sources.

To determine whether a certain file or link is malicious, use ANY.RUN. It is a malware sandbox that provides users with the ability to interact with the samples at hand in a safe cloud environment. For instance, PrivateLoader usually comes packed into a passworded archive. ANY.RUN lets you easily open it, extract the contents, and run them as if you were using your own computer to expose any harmful behavior and collect IOCs.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

Cerber screenshot
Cerber
cerber
Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.
Read More
Pay2Key screenshot
Pay2Key is a ransomware strain primarily written in C++ for Windows (with recent Linux variants), attributed to Iranian-linked actors, notably the Fox Kitten APT group (also known as UNC757 or related operations). First observed in late 2020, it employs double-extortion tactics (encrypting files and threatening to leak stolen data) while showing signs of both financial and state-aligned motivations. It has resurfaced in campaigns targeting Western organizations, including rapid encryption attacks on healthcare.
Read More
SolarisLoader screenshot
SolarisLoader
solaris
SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It utilizes a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes. To remain undetected, the malware patches internal Windows monitoring interfaces and isolates the machine from security updates. Finally, it establishes a resilient three-layer persistence mechanism involving scheduled tasks, registry backups, and a watchdog component.
Read More
ValleyRAT screenshot
ValleyRAT
valleyrat
ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group.
Read More
FlowerStorm screenshot
FlowerStorm
flowerstorm
FlowerStorm is a phishing-as-a-service (PhaaS) platform used by cybercriminals to steal Microsoft 365 credentials and bypass multi-factor authentication (MFA) protections through adversary-in-the-middle (AiTM) attacks. Emerging after the disruption of Rockstar2FA in late 2024, FlowerStorm rapidly gained popularity among attackers targeting enterprises across North America and Europe.
Read More
Xeno RAT screenshot
Xeno RAT
xenorat
Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.
Read More