PrivateLoader is a Windows malware loader operated as a pay-per-install distribution service that has been active since at least early 2021. It is commonly associated with SEO-poisoned and cracked-software distribution chains in which victims download password-protected archives and installers masquerading as pirated or free software. The service has been used by multiple threat actors to deliver a broad range of follow-on payloads, especially information stealers, but also banking trojans, remote-access trojans, spambots, proxy bot malware, cryptominers, secondary loaders, and ransomware.
PrivateLoader functions as a multi-stage loader with components that download and execute additional modules and payloads. Reported behavior includes persistence through scheduled tasks, self-updating, repeated reinfection activity, anti-analysis measures, and impairment of defenses including Windows Defender tampering. It has also been observed performing system and environment checks, using encrypted or obfuscated HTTP communications, and selectively delivering payloads based on victim attributes such as geography, installed software, and other environmental characteristics.
PrivateLoader has been linked to large-scale crimeware distribution and has delivered families including RedLine, RisePro, SmokeLoader, Amadey, IcedID, Tofsee, Socks5Systemz, STOP/DJVU, Vidar, Raccoon, DanaBot, QakBot, Dridex, and others. In some observed chains, it acted as the primary orchestrator for multi-malware infections that combined credential theft, browser-data theft, proxy-bot deployment, cryptomining, persistence, and eventual ransomware execution. It has also been used to distribute proxy botnets and spambots, underscoring its role as a general-purpose criminal malware delivery platform rather than a single-purpose payload.
Telemetry and reporting indicate worldwide victimization, with notable prevalence in parts of Asia, Africa, and South America. Researchers have described PrivateLoader as a high-volume loader ecosystem responsible for very large infection counts and sustained daily install rates. Its operational model, broad customer base, and recurring use in cracked-software ecosystems make it a significant enabler of commodity cybercrime on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
New Actor for win.privateloader ... description = "Detects win.privateloader." ... reference = "https://tavares.re/blog/2022/06/06/hunting-privateloader-pay-per-install-service"
PrivateLoader is a loader from a pay-per-install malware distribution service that has been utilized to distribute info stealers, banking trojans, loaders, spambots, rats, miners and ransomware on Windows machines.
PrivateLoader is one of the most widely used loaders in 2022. It is used by a Pay-Per-Install service to deploy multiple malicious payloads on the infected hosts. First observed in May 2021, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
PrivateLoader was seen being distributed through SEO-optimized websites that claim to provide cracked software. Victims download a password-protected zip file (the password is in the file name) which contains an NSIS installer that executes many malicious payloads, including PrivateLoader.
The service module takes care of persistence by creating a scheduled task
The service module takes care of persistence by creating a scheduled task
Some samples are not being detected because they are packed and this rule will only work on unpacked samples or in memory dumps, for the more recent versions.
This file is responsible for setting up the persistence and injecting the proxy bot in memory.
System checks before starting the malware symphony ... T1016: System Network Configuration Discovery
the customers of the service are able to selectively deliver malware to victims based on location, financial activity, environment, and specific software installed
the malware has additional capabilities, such as disabling Windows Defender, the discovery of user-sensitive data, and many anti-analysis techniques
Process 4440 is also seen communicating with its C2 server, 185[.]216.70.235 and 195.20.16[.]45 via port 80 (T1071 – Application Layer Protocol).
it will output most of the encrypted strings, more than 1500, including the current PrivateLoader C2 IP addresses at the time of writing of this blog post
These domains are simply proxies but behind them sits a massive operation performing millions of loads for various customers.
In the first stage, the loader is executed, which downloads and executes the second stage, the core module. The core module's primary purpose is to download and execute more malware, including another PrivateLoader module named service.
862 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pay-per-install botnet/loader referenced as having been used to mass-install the PEER2PROFIT SDK.
A pay-per-install botnet/loader referenced as being used to mass-install the PEER2PROFIT SDK.
Pay-per-install loader used to deliver additional malware.
Referenced only in appendix literature as malware associated with the rise of a proxy service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.