Loader
HijackLoader
aka DOILoader · GHOSTPULSE · IDAT Loader · SHADOWLADDER
According to Rapid7, this is a loader first spotted in July 2023.
According to Rapid7, this is a loader first spotted in July 2023. It implements several evasion techniques including Process Doppelgänging, DLL Search Order Hijacking, and Heaven's Gate. It has been observed to store its malicious payload in the IDAT chunk of PNG file format.
Family metadata imported from Malpedia (Fraunhofer FKIE).