PrivateLoader distributes other malware through a pay-per-install service. This February 2024 investigation follows changes in its communication protocol and string obfuscation, including samples protected by VMProtect.
The walkthrough starts with a sample initially classified as RisePro. Network analysis instead pointed to an updated PrivateLoader build. A failed attempt to apply the known decryption method led to the discovery of a different XOR-based protocol, followed by deeper analysis and updated detection.
The article shares YARA and Suricata rules and reports the team’s available infection telemetry. Its observations belong to the publication period and the team’s partial visibility, rather than a current census of the botnet.
