Hijack Loader Malware Employs Process Hollowing, UAC Bypass in Latest Version
ID: ddf4fb5b-76c4-5d2f-9d90-1646c2f7db00
STIX ID: report--ddf4fb5b-76c4-5d2f-9d90-1646c2f7db00
Feed Name: The Hacker News
A technical report describes an updated variant of the Hijack Loader (IDAT Loader) observed in March–April 2024 that incorporates multiple new anti-analysis and evasion techniques — including Windows Defender exclusions via PowerShell, UAC bypass, process hollowing, Heaven's Gate to evade user-mode hooks, and decrypting/parsing PNG files to load a second-stage payload — and is being used to deliver information stealers (Amadey, Lumma, Meta, Racoon) and RATs (Remcos, Rhadamanthys) across campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
