logo

Cybercriminals Exploit Free Software Lures to Deploy Hijack Loader and Vidar Stealer

ID: e30a1123-8abb-5ae2-b2cc-45903204e25c

STIX ID: report--e30a1123-8abb-5ae2-b2cc-45903204e25c

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-18

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Threat actors are distributing malware through pirated or fake installers, SEO-poisoned sites, and malicious HTML attachments to deliver loaders (Hijack Loader/DOILoader) that sideload and drop information stealers (Vidar, Lumma, SolarMarker) as well as follow-on payloads like Amadey, miners (XMRig), clippers, and remote access tools; the campaigns employ DLL side-loading, UAC bypass via CMSTPLUA, PowerShell/AutoIt scripts, and clipboard/HTML social-engineering techniques to evade detection and escalate privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.