Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

GMX hacker returns stolen funds after bounty negotiation 

July 12, 2025

Weekly Crypto Regulation Roundup: Trump Slams Musk, Tim Scott Backs Blockchain, and Broker Rule Gets Buried

July 12, 2025

Trader Outlines Catalysts That Could Trigger 350% Bitcoin Rally, Updates Outlook on Ethereum and Avalanche

July 12, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    BlackRock’s ETHA Books Record Inflow as ETFs Attract $700M This Week

    July 12, 2025

    KULR Technology Increases Bitcoin Holdings To $101 Million

    July 11, 2025

    Analysts Predict Bitcoin to Hit $140K With Strong Momentum 

    July 11, 2025

    $687,220,000 in Bitcoin Shorts Liquidated in Just One Hour As BTC Explodes To $116,000

    July 11, 2025

    Trader Outlines Catalysts That Could Trigger 350% Bitcoin Rally, Updates Outlook on Ethereum and Avalanche

    July 12, 2025

    Ethereum Price Poised for $4,000 Rally

    July 11, 2025

    Breakout Above $2,800 Could Ignite Altseason

    July 11, 2025

    Ethereum: What’s standing between ETH and $3K? – Data suggests…

    July 11, 2025

    XRP Price Rallies 10%, Yet 2,000 Traders FOMO This AI Presale

    July 12, 2025

    Zero-Knowledge Proof Altcoin Lagrange (LA) Crashes Following Announcement of New Binance Listing

    July 11, 2025

    Hyperliquid to onboard 10M Phantom users – Will HYPE hit $120 now?

    July 11, 2025

    Bitcoin Uptrend Intact, But Binance Activity Warns Of Short-Term Pullback

    July 11, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    GMX hacker returns stolen funds after bounty negotiation 

    July 12, 2025

    Weekly Crypto Regulation Roundup: Trump Slams Musk, Tim Scott Backs Blockchain, and Broker Rule Gets Buried

    July 12, 2025

    Trader Outlines Catalysts That Could Trigger 350% Bitcoin Rally, Updates Outlook on Ethereum and Avalanche

    July 12, 2025

    BlackRock’s ETHA Books Record Inflow as ETFs Attract $700M This Week

    July 12, 2025
  • DeFi

    GMX hacker returns stolen funds after bounty negotiation 

    July 12, 2025

    Opyn’s top minds defect to Coinbase in strategic shift toward onchain derivatives

    July 11, 2025

    SEI targets 55% rally as native USDC support sparks inverse H&S breakout

    July 11, 2025

    Robinhood launches ETH, SOL staking services for US users with $1 minimum

    July 11, 2025

    Corporate Bitcoin holdings hit $91B as Q2 sees record surge in adoption

    July 11, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Weekly Crypto Regulation Roundup: Trump Slams Musk, Tim Scott Backs Blockchain, and Broker Rule Gets Buried

    July 12, 2025

    OpBNB Dominates in Blockchain Gaming UAWs, SKALE, RONIN, SEI, WAX & Other Ranked Top Performers

    July 12, 2025

    Crypto-Stealing Malware Surges as Scammers Impersonate AI, Web3 Startups — Here’s the Catch

    July 11, 2025

    German State Bank Issues €100M Bond on Polygon – Is TradFi Finally Embracing Crypto?

    July 11, 2025

    Chinese industry group warns Web3 and DeFi high-return deals hide classic Ponzi engines

    July 11, 2025

    Scam targets dormant Bitcoin wallets with fake legal notice

    July 9, 2025

    North Korean Hackers Target Crypto Firms with Novel macOS Malware

    July 3, 2025

    Crypto firms paid $2.7M monthly to North Korean workers

    July 3, 2025

    GMX hacker returns stolen funds after bounty negotiation 

    July 12, 2025

    Weekly Crypto Regulation Roundup: Trump Slams Musk, Tim Scott Backs Blockchain, and Broker Rule Gets Buried

    July 12, 2025

    Trader Outlines Catalysts That Could Trigger 350% Bitcoin Rally, Updates Outlook on Ethereum and Avalanche

    July 12, 2025

    BlackRock’s ETHA Books Record Inflow as ETFs Attract $700M This Week

    July 12, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Best Crypto Casino Review Websites for Bitcoin & No-KYC Gamblers in 2025

    July 12, 2025

    DNS Records Explained: A Beginner’s Guide to A, CNAME, TXT, and More

    July 11, 2025

    Top Trends Transforming the Sensor Fusion Market Landscape in 2025: Technological Advancements In Sensor Fusion Technology Transform Market Presence

    July 11, 2025

    .cgai — Protect Your Images from Theft and Public Misuse

    July 11, 2025

    Blazpay and Onmi AR Unite to Elevate Web3 Gaming Experience

    July 11, 2025

    ChatGPT vs X: Who Sees Crypto Narratives First?

    July 10, 2025

    Floki’s Valhalla Surpasses 100K Veras Minted Within Days of Launch

    July 10, 2025

    Gear Runner Integrates with Meta Arena to Deliver Gamified Real-World Activity and Move to Earn for GameFi Fans

    July 10, 2025

    GMX hacker returns stolen funds after bounty negotiation 

    July 12, 2025

    Weekly Crypto Regulation Roundup: Trump Slams Musk, Tim Scott Backs Blockchain, and Broker Rule Gets Buried

    July 12, 2025

    Trader Outlines Catalysts That Could Trigger 350% Bitcoin Rally, Updates Outlook on Ethereum and Avalanche

    July 12, 2025

    BlackRock’s ETHA Books Record Inflow as ETFs Attract $700M This Week

    July 12, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Malta’s MiCA license process under scrutiny by EU regulators

    July 12, 2025

    Tornado Cash Judge Won’t Let One Case Be Mentioned in Roman Storm’s Trial: Here’s Why

    July 12, 2025

    6 Best Anonymous Crypto Wallets: Hide your Identity Legally

    July 11, 2025

    US Senate targets Bukele’s El Salvador, bill calls to sanction BTC strategy

    July 11, 2025

    Bitcoin treasury adoption up 3x YoY, corporates accumulated 725,000 BTC so far

    July 11, 2025

    Circle’s USDC aims for China breakthrough with Ant Group alliance

    July 10, 2025

    SharpLink stock continues surging as treasury tops 200k Ethereum

    July 10, 2025

    Rex-Osprey spot Solana ETF doubles cumulative inflows to $41M on July 8

    July 10, 2025

    GMX hacker returns stolen funds after bounty negotiation 

    July 12, 2025

    Weekly Crypto Regulation Roundup: Trump Slams Musk, Tim Scott Backs Blockchain, and Broker Rule Gets Buried

    July 12, 2025

    Trader Outlines Catalysts That Could Trigger 350% Bitcoin Rally, Updates Outlook on Ethereum and Avalanche

    July 12, 2025

    BlackRock’s ETHA Books Record Inflow as ETFs Attract $700M This Week

    July 12, 2025
  • Analysis

    Omni Network Price Skyrockets 164%, Should You Buy Now?

    July 11, 2025

    Memecoin platform Pump.fun targets third-largest token sale in history

    July 11, 2025

    Anthony Scaramucci Says $180,000 Bitcoin Price Explosion Possible As BTC ‘Supremacy’ Creeps Up – Here’s His Timeline

    July 11, 2025

    Can Bulls Push DOGE Price to $0.22?

    July 11, 2025

    HyperLiquid breaks $8 billion daily trading volume pushing HYPE token near all-time highs

    July 10, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Tokenization?

    July 11, 2025

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    June 16, 2025

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Trump crypto holdings edge higher as WLFI pushes for open trading

    July 12, 2025

    Coinbase partners with Perplexity for real-time crypto insights via AI

    July 11, 2025

    Rumble teams up with MoonPay to power crypto-fiat wallet integration

    July 11, 2025

    GMX suffers $42M hack, issues 10% bounty offer to hacker

    July 10, 2025

    GMX hacker returns stolen funds after bounty negotiation 

    July 12, 2025

    Weekly Crypto Regulation Roundup: Trump Slams Musk, Tim Scott Backs Blockchain, and Broker Rule Gets Buried

    July 12, 2025

    Trader Outlines Catalysts That Could Trigger 350% Bitcoin Rally, Updates Outlook on Ethereum and Avalanche

    July 12, 2025

    BlackRock’s ETHA Books Record Inflow as ETFs Attract $700M This Week

    July 12, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»Threat Actors Target Victims with HijackLoader and DeerStealer
Threat Actors Target Victims with HijackLoader and DeerStealer
Security and Privacy

Threat Actors Target Victims with HijackLoader and DeerStealer

June 17, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A recent surge in cyber-attacks has been detected by cybersecurity experts, with HijackLoader and DeerStealer being used in phishing campaigns to trick victims into executing harmful commands.

The eSentire’s Threat Response Unit (TRU) uncovered this new tactic, which starts with the use of ClickFix to gain initial access. Victims are directed to a phishing page where they are instructed to run a PowerShell command through the Windows Run prompt. This command triggers the download of an installer named now.msi, setting off a series of actions that ultimately lead to the deployment of HijackLoader and the release of the DeerStealer payload.

HijackLoader, which has been active since 2023, is known for its utilization of steganography, specifically concealing configuration data within PNG images. Once activated, the loader exploits legitimate binaries to execute unsigned malicious code, paving the way for DeerStealer to be injected into memory.

DeerStealer, also known as XFiles Spyware in dark-web circles, is a subscription-based infostealer that offers a wide range of theft capabilities beyond basic credential harvesting. This malware can extract data from over 50 web browsers, intercept 14+ types of cryptocurrency wallets through clipboard monitoring, gather credentials from various messaging platforms, and even provide stealthy remote access through hidden VNC functionality. Additionally, DeerStealer employs encrypted HTTPS channels for command-and-control communication, making detection and analysis more challenging.

The attack involves a series of encoded commands that fetch the installer, utilizing a signed binary from COMODO that loads a manipulated DLL to hijack execution. Despite the availability of tools to decode HijackLoader’s configuration, attackers continue to utilize these methods, highlighting their indifference to detection risks.

See also  Alleged Crypto-Stealing SIM Swap Duo Charged

eSentire has cautioned that DeerStealer is constantly evolving, with future enhancements set to include MacOS compatibility, AI-driven improvements, and expanded client targets. Threat actors who opt for higher-priced tiers of up to $3000 per month gain access to features such as re-encryption, payload signing, and advanced customization.

In light of these developments, eSentire’s TRU advises organizations to maintain continuous threat monitoring and update their endpoint protection measures to detect emerging loaders and stealers before any harm is inflicted. As cyber threats become more sophisticated, staying vigilant is crucial to safeguarding sensitive data and systems.

Actors DeerStealer HijackLoader target Threat Victims
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Chinese industry group warns Web3 and DeFi high-return deals hide classic Ponzi engines

July 11, 2025

Fundstrat’s Tom Lee Says FOMO Driving Major Stock Market Rally – Here’s His S&P 500 Price Target

July 10, 2025

Ethereum Price Soars on $148M Inflows as Bulls Target $2,610 Breakout?

July 10, 2025

Scam targets dormant Bitcoin wallets with fake legal notice

July 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Trump’s ‘Big Beautiful Bill’ Passes Senate—Without Bitcoin Tax Exemptions

July 3, 2025

Sky Mavis co-founder accuses Ronin game of making secret deal

April 29, 2025

Bitget Token (BGB) Soars to $7,869,959,009 Market Cap With Suprise 844% Rally This Year

December 26, 2024
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

GMX hacker returns stolen funds after bounty negotiation 

July 12, 2025

Weekly Crypto Regulation Roundup: Trump Slams Musk, Tim Scott Backs Blockchain, and Broker Rule Gets Buried

July 12, 2025

Trader Outlines Catalysts That Could Trigger 350% Bitcoin Rally, Updates Outlook on Ethereum and Avalanche

July 12, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.