Skip to content

Loader

HijackLoader

aka DOILoader · GHOSTPULSE · IDAT Loader · SHADOWLADDER

According to Rapid7, this is a loader first spotted in July 2023.

HijackLoader, also known as DOILoader, GHOSTPULSE, IDAT Loader, SHADOWLADDER, is a Windows loader.

Background

Rapid7 reports that this loader was first observed in July 2023. It employs a range of evasion methods such as Process Doppelgänging, DLL Search Order Hijacking, and Heaven's Gate. Analysts have seen it conceal its malicious payload within the IDAT chunk of the PNG file format.


Source: Malpedia (Fraunhofer FKIE).