Rugmi is a malware loader ecosystem also tracked as HijackLoader and IDAT Loader. The content describes it as a Malware-as-a-Service/pay-per-install loader first observed in 2023 and used to deliver a range of follow-on malware, including Aurora Stealer, Rhadamanthys Stealer, SectopRAT, DanaBot, CryptBot, Vidar Stealer, DeerStealer, and LummaStealer. It is also listed among payloads distributed within the broader Amadey ecosystem.
Observed Rugmi/HijackLoader tradecraft includes multi-stage delivery, custom binary container formats, aggressive DLL sideloading using legitimate signed binaries such as Sysinternals tcpvcon.exe and a jpegoptim-themed launcher, DLL search-order hijacking via malicious pla.dll and d3d9.dll/Register.dll, runtime API resolution, Living-off-the-Land execution via MSBuild.exe, process injection into explorer.exe, persistence via %LOCALAPPDATA%\RaScope.exe and the Windows Startup folder, and reported modules for UAC bypass and scheduled task creation. In one analyzed Stage 4 sample, the final payload was Aurora Stealer, assessed to steal browser credentials from Chrome, Firefox, and Edge, harvest cookies and session tokens, steal cryptocurrency wallets, and exfiltrate files. The sample contained campaign identifier xy_Alt_betav1 and used a custom configuration referencing the UploadValidate export and %windir%\SysWOW64\pla.dll.
The content also links Rugmi to affiliate-driven social-engineering operations. One analyzed WiX Burn bundle first observed on 2026-03-15 delivered DeerStealer while displaying a legitimate Active@ Password Changer decoy; the report assesses it as a DeerStealer affiliate campaign operating within the Rugmi loader ecosystem and likely distributed via malvertising targeting users searching for password-management tools. Related infrastructure noted in the content includes shift-art.com resolving to 37.140.192.197 for Rugmi MSI delivery. Additional reporting cited in the content states that LummaStealer operators have used Rugmi as an initial loader before later shifting to other loaders such as DonutLoader and CastleLoader. The content further notes related IDAT Loader campaigns targeting Ukrainian organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"Our analysis shows that LummaStealer infections are primarily driven by social engineering rather than by the exploitation of technical vulnerabilities. Malware campaigns consistently rely on users unwittingly running infected files, using simple lures such as fake cracked software, fake games or media downloads, and abuse of trusted platforms."
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rugmi is mentioned as a payload distributed by a large botnet cluster within the Amadey ecosystem.
Rugmi is referenced as the loader ecosystem used by the affiliate to deliver DeerStealer through malvertising and deceptive software installers.
Referenced only as part of related infrastructure in the broader cluster; the content does not provide further malware functionality details.
A MaaS/pay-per-install loader ecosystem that uses DLL sideloading, LoTL via MSBuild.exe, persistence through the Startup folder, process injection, and staged payload delivery. In this sample it delivers Aurora Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.