logo

Threat Actors Target Victims with HijackLoader and DeerStealer

ID: 3ddc67dc-3f13-542e-b583-d27bb31d3da8

STIX ID: report--3ddc67dc-3f13-542e-b583-d27bb31d3da8

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-06-16

Date Updated: 2026-04-22

...
...

**Executive Summary:** eSentire’s Threat Response Unit observed a phishing campaign that uses ClickFix to trick victims into running an MSI which leverages a signed binary and DLL hijacking to launch HijackLoader; the loader uses steganography and process injection to deploy DeerStealer, a subscription-based infostealer capable of stealing credentials from 50+ browsers, multiple crypto wallets, messaging and email clients, and offering hidden VNC and encrypted C2 communications—threat actors are actively evolving the tool and providing advanced features to paying subscribers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.