Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Short-term bitcoin holders send $1.8 billion in BTC to exchanges after $74,000 rally

March 6, 2026

OAM crypto database end raises concerns as Italy prepares for MiCAR European passport

March 6, 2026

Is XRP Price Preparing for $4 Breakout as 44M Tokens Leave Binance?

March 6, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Short-term bitcoin holders send $1.8 billion in BTC to exchanges after $74,000 rally

    March 6, 2026

    Solo Satoshi Launches Bitaxe Turbo Touch, An Open-Source Touchscreen Bitcoin Miner

    March 6, 2026

    Bitcoin holds $70K, but BTC bull market isn’t back: Here’s why

    March 6, 2026

    Bitcoin Miners Sell 15K BTC After $126K High, Is This the Reason Why Bitcoin is Dropping

    March 6, 2026

    Top Analyst Reveals What’s Next For Bitcoin, Ethereum and XRP

    March 5, 2026

    Ethereum Price Analysis: Institutional Buying Returns as Whales Accumulate

    March 5, 2026

    Ethereum Hovers at $2,150 — Can ETH Price Rally to $2,400 or Stall Below $2,200?

    March 5, 2026

    Vitalik Buterin Admits Ethereum Hasn’t Meaningfully Improved People’s Lives

    March 5, 2026

    Bitcoin Rally May Be Setting Up A Macro Lower High, Analyst Says

    March 6, 2026

    Bank Resistance Puts 2026 Passage Of Crypto Market Structure Bill In Doubt, Reuters

    March 6, 2026

    How Extreme Negative Funding Is Priming XRP For A High-Velocity Trend Reversal

    March 6, 2026

    Bitcoin Liquidity Set To Expand With Morgan Stanley BTC ETF Option

    March 6, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    US Ranks #1 in CoinGecko Global Meme Coin Interest Report

    December 18, 2025

    Short-term bitcoin holders send $1.8 billion in BTC to exchanges after $74,000 rally

    March 6, 2026

    OAM crypto database end raises concerns as Italy prepares for MiCAR European passport

    March 6, 2026

    Is XRP Price Preparing for $4 Breakout as 44M Tokens Leave Binance?

    March 6, 2026

    Western Union teams up with Crossmint to expand USDPT stablecoin access on Solana

    March 6, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Western Union teams up with Crossmint to expand USDPT stablecoin access on Solana

    March 6, 2026

    The Protocol: New Ethereum scaling plans

    March 6, 2026

    EtherMail adds email identity for AI agents

    March 6, 2026

    Pi Network Co-Founder Unveils Crucial KYC Updates Every Pioneer Needs to Know

    March 6, 2026

    Leaked Database Sheds Light on Iranian Crypto Sanctions Evasion

    March 4, 2026

    DOJ seizures of $580M expose how crypto investment scams scaled into shift work with quotas and scripts

    March 3, 2026

    Aeternum Botnet Shifts Command Control to Polygon Blockchain

    February 27, 2026

    Former Defense Contractor Boss Gets 7+ Years for Selling Zero Days

    February 26, 2026

    Short-term bitcoin holders send $1.8 billion in BTC to exchanges after $74,000 rally

    March 6, 2026

    OAM crypto database end raises concerns as Italy prepares for MiCAR European passport

    March 6, 2026

    Is XRP Price Preparing for $4 Breakout as 44M Tokens Leave Binance?

    March 6, 2026

    Western Union teams up with Crossmint to expand USDPT stablecoin access on Solana

    March 6, 2026
  • Web 3
    1. Gaming
    2. View All

    Crypto Payroll in 2026: Stablecoins Are Rewiring Global Paychecks

    March 6, 2026

    SuperRare Liquid Editions: The Next Evolution of NFTs

    March 6, 2026

    METYA Partners With Kult Games to Expand Web3 Gaming Ecosystem

    March 6, 2026

    AurumX Collaborates with FishWar to Redefine Web3-Based Gaming Economies

    March 5, 2026

    Short-term bitcoin holders send $1.8 billion in BTC to exchanges after $74,000 rally

    March 6, 2026

    OAM crypto database end raises concerns as Italy prepares for MiCAR European passport

    March 6, 2026

    Is XRP Price Preparing for $4 Breakout as 44M Tokens Leave Binance?

    March 6, 2026

    Western Union teams up with Crossmint to expand USDPT stablecoin access on Solana

    March 6, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    OAM crypto database end raises concerns as Italy prepares for MiCAR European passport

    March 6, 2026

    Bitcoin volatility could explode in April as SEC reviews the market behind ETF leverage

    March 6, 2026

    Russian Central Bank Proposes Allowing Banks and Brokers to Obtain Crypto Licenses

    March 6, 2026

    Strategic Move Brings Former FINRA Examiner Justin Vose to Lead RWA Regulation

    March 6, 2026

    XRP and XRPL get a credibility lift from Ripple’s expanding footprint

    March 5, 2026

    XRP rewrites the playbook for altcoin ETF approvals to surge in late 2026 after a wave of futures listings

    March 4, 2026

    Bitcoin ETF custody concentrates power in one place, and now a single operational failure causes dangerous ripples

    March 3, 2026

    Revolut’s stablecoin test targets its 12M UK users

    March 3, 2026

    Short-term bitcoin holders send $1.8 billion in BTC to exchanges after $74,000 rally

    March 6, 2026

    OAM crypto database end raises concerns as Italy prepares for MiCAR European passport

    March 6, 2026

    Is XRP Price Preparing for $4 Breakout as 44M Tokens Leave Binance?

    March 6, 2026

    Western Union teams up with Crossmint to expand USDPT stablecoin access on Solana

    March 6, 2026
  • Analysis

    Is XRP Price Preparing for $4 Breakout as 44M Tokens Leave Binance?

    March 6, 2026

    Bitcoin miners’ AI pivot draws billion-dollar Wall Street bets

    March 6, 2026

    JPMorgan Chase Says One Asset Could ‘Quickly’ Surge Amid Middle East Conflict – And It’s Not Oil or Gold

    March 6, 2026

    XRP Price Consolidates Under $1.5 — What Could Drive the Next Move to $2?

    March 5, 2026

    Israel’s weekly $3B Iran war cost equals over 41,000 Bitcoin

    March 5, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    What Are Prediction Markets? How Polymarket, Kalshi and Myriad Work

    February 13, 2026

    What Is Farcaster? The Decentralized Social Media Protocol

    February 10, 2026

    What Is Venice AI? The Privacy-Focused Chatbot

    January 13, 2026

    Crypto platform aims to let retail investors buy IPO shares at the same price as Wall Street insiders

    March 6, 2026

    The company holding all Bitcoin ETF coins is losing money, resurfacing questions about centralization

    February 21, 2026

    The Bitcoin CME gap will now close forever in May leaving a return to $84k hanging

    February 21, 2026

    Robinhood’s $221 million crypto revenue drop shows crypto winter isn’t on chain and retail already moved

    February 16, 2026

    Short-term bitcoin holders send $1.8 billion in BTC to exchanges after $74,000 rally

    March 6, 2026

    OAM crypto database end raises concerns as Italy prepares for MiCAR European passport

    March 6, 2026

    Is XRP Price Preparing for $4 Breakout as 44M Tokens Leave Binance?

    March 6, 2026

    Western Union teams up with Crossmint to expand USDPT stablecoin access on Solana

    March 6, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Threat Actors Target Victims with HijackLoader and DeerStealer
Threat Actors Target Victims with HijackLoader and DeerStealer
Security and Privacy

Threat Actors Target Victims with HijackLoader and DeerStealer

September 9, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A new wave of cyber-attacks involving HijackLoader and DeerStealer has been observed by cybersecurity researchers using phishing tactics to lure victims into executing malicious commands.

According to the eSentire’s Threat Response Unit (TRU), which discovered the campaign, it uses ClickFix as the initial access vector.

Victims are redirected to a phishing page that prompts them to run a PowerShell command via the Windows Run prompt. This command downloads an installer named now.msi, which launches a chain of actions culminating in the execution of HijackLoader and release of the DeerStealer payload.

eSentire said HijackLoader has been active since 2023 and is known for its use of steganography, specifically hiding configuration data in PNG images.

Once executed, the loader exploits legitimate binaries to run unsigned malicious code, ultimately injecting DeerStealer into memory.

DeerStealer’s Expansive Theft Capabilities

DeerStealer, also marketed as XFiles Spyware on dark-web forums by a user named LuciferXfiles, is a subscription-based infostealer with features that go well beyond basic credential theft.

The malware:

  • Extracts data from over 50 web browsers

  • Hijacks 14+ cryptocurrency wallet types via clipboard monitoring

  • Harvests credentials from messengers, FTP, VPN, email and gaming clients

  • Includes hidden VNC for stealthy remote access

  • Uses encrypted HTTPS channels for command-and-control (C2) communication

The malware also features modular obfuscation and virtual machines to decrypt strings, hindering traditional analysis techniques.

Read more on malware loader techniques: CoffeeLoader Malware Loader Linked to SmokeLoader Operations

Command Line Trickery

The attack begins with the user unwittingly running an encoded command that fetches the installer. 

Though the installer uses a signed binary from COMODO, it loads a manipulated DLL to hijack execution. This altered DLL eventually decrypts the next stage, which injects DeerStealer into another legitimate process.

See also  US Takes Down Illegal Cryptocurrency Mixing Service Samourai Wallet

Despite public tools available to decode HijackLoader’s configuration, attackers continue using the same methods, indicating either ignorance or disregard for detection risks.

Expanding Threat, Evolving Tools

eSentire warned that DeerStealer is continuously evolving, with upcoming features to include MacOS support, AI-driven enhancements and additional client targets.

Threat actors who subscribe to higher pricing tiers – up to $3000 per month – receive extras such as re-encryption, payload signing and advanced customization.

As these tools become more sophisticated, defenders must remain alert.

eSentire’s TRU recommends continuous threat monitoring and updating endpoint protection mechanisms to detect emerging loaders and stealers before any damage is done.

Actors DeerStealer HijackLoader target threat Victims
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Is $0.032 the Next Target?

March 5, 2026

Leaked Database Sheds Light on Iranian Crypto Sanctions Evasion

March 4, 2026

DOJ seizures of $580M expose how crypto investment scams scaled into shift work with quotas and scripts

March 3, 2026

Seasoned Trader Says Final Bitcoin Flush Is Coming, Here’s The Target

March 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ethereum bulls lead, $14M shorts liquidated – $5000 in sight?

September 14, 2025

Base App shifts to trading-first model to power the onchain economy

January 16, 2026

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Short-term bitcoin holders send $1.8 billion in BTC to exchanges after $74,000 rally

March 6, 2026

OAM crypto database end raises concerns as Italy prepares for MiCAR European passport

March 6, 2026

Is XRP Price Preparing for $4 Breakout as 44M Tokens Leave Binance?

March 6, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.