Researchers reported that HijackLoader is being distributed through pirated software download lures, with victims redirected across multiple domains before retrieving MEGA-hosted archives containing a staged loader. The campaign was not limited to a single piracy site; investigators said similar cracked-software promotions also appeared on platforms such as TIDAL, broadening the reach of the infection chain.
The analyzed sample used a hijacked DLL, encrypted configuration files, and layered evasion techniques including module stomping, stack spoofing, syscall indirection, anti-analysis checks, and unhooking routines. After establishing persistence and attempting UAC bypass, the malware used multiple process-injection paths to deploy a final payload, with LummaC2 identified as the most commonly observed payload in recent activity, although HijackLoader has previously delivered other malware families as well.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Trellix published an analysis of a HijackLoader infection chain in which users seeking pirated software were redirected through multiple domains to a MEGA-hosted archive that deployed a staged loader. The report detailed techniques including DLL hijacking, encrypted configuration files, module stomping, stack spoofing, syscall indirection, anti-analysis checks, unhooking, persistence, UAC bypass logic, and delivery of a final payload such as LummaC2.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.