Threat Actors Target Victims with HijackLoader and DeerStealer
ID: 3ddc67dc-3f13-542e-b583-d27bb31d3da8
STIX ID: report--3ddc67dc-3f13-542e-b583-d27bb31d3da8
Feed Name: Infosecurity Magazine (News)
**Executive Summary:** eSentire’s Threat Response Unit observed a phishing campaign that uses ClickFix to trick victims into running an MSI which leverages a signed binary and DLL hijacking to launch HijackLoader; the loader uses steganography and process injection to deploy DeerStealer, a subscription-based infostealer capable of stealing credentials from 50+ browsers, multiple crypto wallets, messaging and email clients, and offering hidden VNC and encrypted C2 communications—threat actors are actively evolving the tool and providing advanced features to paying subscribers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
