logo

HijackLoader Updates

ID: e47eaae5-22f9-5bb5-a7ea-dfd456489edd

STIX ID: report--e47eaae5-22f9-5bb5-a7ea-dfd456489edd

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

This report provides a technical analysis of HijackLoader, a modular Windows loader that decrypts and decompresses embedded or downloaded PNG-steganographed modules to execute a second-stage 'ti' module which performs process hollowing and injects a main instrumentation payload; it details first- and second-stage logic, hashing and decryption routines (SDBM, CRC-32, XOR), LZNT1 decompression, module names and hashes, anti-analysis/evasion techniques (Heaven's Gate, direct syscalls, UAC bypass, Defender exclusion), and observable indicators (process names, hashes, and a URL).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.