216.73.217.22

New HijackLoader Evasion Tactics

· Published 31/03/2025 19:05 · Modified 01/04/2025 10:27

Export JSON

Essential information

Published
31/03/2025 19:05
Modified
01/04/2025 10:27
Tags
2025-03-31 anti-vm call stack spoofing evasion hijackloader modular persistence virtual machine detection
Related entities
11 techniques (mitre), 1 malware

Description

, a malware loader discovered in 2023, has evolved with new modules and tactics. Recent updates include to mask function call origins, to identify analysis environments, and establishment via scheduled tasks. The loader now implements checks, mutex creation, custom injection paths, and additional modules for various functions. Notable changes include the addition of new blocklisted processes and modifications to module decryption methods. 's nature and continuous updates suggest ongoing efforts to enhance its anti-detection capabilities and complicate analysis.

External references