logo

New HijackLoader Evasion Tactics

ID: 4ccd88f6-340e-514e-bdc3-b8122200a3f3

STIX ID: report--4ccd88f6-340e-514e-bdc3-b8122200a3f3

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

This report provides a technical analysis of HijackLoader, a sophisticated Windows loader that employs advanced evasion (call-stack spoofing, Heaven's Gate switching to x64 direct syscalls, remapping ntdll/wow64cpu), anti-VM checks, and persistence via scheduled tasks. It enumerates newly observed modules (ANTIVM, MUTEX, CUSTOMINJECT, CUSTOMINJECTPATH, modTask/modTask64, PERSDATA, SM, TinycallProxy/TinycallProxy64), configuration and structure definitions (ANTIVM_STRUCT, PERSDATA_STRUCT, DIRECTSYSCALL_STRUCT), blocklisted processes, and module CRCs and behaviors that serve as actionable indicators and TTP documentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.