A metallic spider on a chip beside encrypted fragments and exposed circuit paths

Hunting PrivateLoader: The Malware Behind InstallsKey PPI Service

Tracing changes in PrivateLoader protocols and string obfuscation, with YARA and Suricata detection.

Research article · February 27, 2024
A loader distributing different payloads through branching connections

Tracking PrivateLoader: Malware Distribution Service

Tracking PrivateLoader delivery chains and identifying 30 malware families in the collected payloads.

Research article · August 31, 2022
Two memory stacks combining to unlock hidden data inspected through a magnifying glass

Decrypting and Hunting PrivateLoader

Building a PrivateLoader string decryptor and YARA rule from a stack-based XOR pattern.

Technical walkthrough · June 6, 2022 · 4 min read