Urban Vidergar
Malware Reverse Engineer, Incident Responder. Cyber Security Specialist @ SI-CERT
Session
03-29
12:40
30min
Dissecting HijackLoader: From Fake CAPTCHA to NTFS Transacted Hollowing
Urban Vidergar
A recent rise in fake CAPTCHA scams has led to a spike in user-triggered infostealer infections resulting in significant cryptocurrency losses among Slovenian victims. The HijackLoader malware abuses steganography to hide its encrypted payload within the PE resource, bypasses user-mode hooks, and executes direct syscalls within its shellcode. It combines NTFS transactions and process hollowing to deliver the final crypto-stealing payload.
P1