HijackLoader: Polymorphic DLL Injection as a Vector for Multi-Stage Attacks - Cybersecurity Conference

HijackLoader: Polymorphic DLL Injection as a Vector for Multi-Stage Attacks

Nowadays, the use of unlicensed and pirated software continues to represent one of the most underestimated yet critically significant threats to both corporate and government sectors worldwide. This challenge is particularly pronounced in the Asia-Pacific region, where the prevalence of unauthorized software distributions and unofficial builds creates favorable conditions for malicious actors. Attackers actively embed malicious code within legitimate application environments, with one of the most prevalent vectors being the substitution of system and user DLL libraries — a technique commonly referred to as DLL-hijacking.

Specialists from Doctor Web daily identify dozens of modified DLL libraries distributed through unofficial installers and patches. Among these, the loader designated as «HijackLoader» is regularly observed, exhibiting polymorphism and the capability to inject malicious code into randomly selected segments of original libraries with minimal disruption to the overall file structure. This renders the modified libraries nearly indistinguishable from their authentic counterparts during surface-level static analysis. Variants of this Trojan are detected by the company with consistent frequency, with the embedded malicious code serving as the initial stage of a multi-phase attack chain. At various stages, the code within the compromised DLL interacts with auxiliary files containing encrypted content, disguised under legitimate extensions such as .csv and .xls — further complicating detection through conventional security mechanisms. Distribution is facilitated via unofficial software portals, torrent resources, as well as fake or compromised websites, where attackers inject code designed to automate the download and deployment of the Trojan onto victim systems.

During the forthcoming presentation, we will conduct a detailed analysis of several variants of the HijackLoader Trojan, examine their behavioral characteristics within compromised operating environments, and demonstrate the interaction of the malicious code with encrypted files, as well as the multi-stage delivery chain for multi-module payloads.

Oleg Gayduk – Doctor Web

Oleg Gayduk joined Doctor Web in 2022 as a malware analyst and was later brought into the botnet research team. He focuses on targeted attacks, botnets, and highly complex threats. He enjoys unraveling multi-stage malware chains, particularly those involving complex loaders, encryption, and unconventional compromise vectors that often go unnoticed.

Maxim Demidenko – Doctor Web

Maxim Demidenko joined Doctor Web in 2019 and currently works as team leader of the Linux malware analysts. His focus is on researching new multiplatform threats and improving the detections. He is passionate about malware analysis, reverse engineering and building machine learning malware detection systems.