Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

DeerStealer Malware Deployed Through Exploitation of Windows Run Prompt by Threat Actors

The eSentire's Threat Response Unit (TRU) has identified a series of malicious campaigns in May 2025 involving the deployment of DeerStealer malware, also known as XFiles Spyware, via the HijackLoader malware loader.

The eSentire's Threat Response Unit (TRU) has identified a series of malicious campaigns in May 2025 involving the deployment of DeerStealer malware, also known as XFiles Spyware, via the HijackLoader malware loader.

The DeerStealer malware is designed to extract sensitive data, including cryptocurrency wallets, browser credentials, VPN details, and instant messaging information.

The attack chain begins with a phishing technique called ClickFix, which tricks users into executing a malicious PowerShell command via the Windows Run Prompt. This leads to the download of DeerStealer as the final payload.

The attack initiates with a redirection to a ClickFix page, prompting users to run an encoded PowerShell script. This script downloads a malicious Microsoft Installer (MSI) file, "now.msi," using curl.exe.

This method exploits legitimate system features, highlighting the evolving tactics of cybercriminals in bypassing traditional security measures.

The attack initiates with a redirection to a ClickFix page, prompting users to run an encoded PowerShell script.
Noah Redmond · Thehackingpost

The installer places files into C:\ProgramData and utilizes a legitimate COMODO Internet Security binary to load a tampered version of cmdres.dll. Through a hooked C runtime function, the HijackLoader is initiated. It uses steganography to store encrypted configurations in PNG images.

The loader resolves APIs dynamically and decrypts subsequent stages from embedded files, eventually injecting DeerStealer into processes via module stomping of legitimate binaries like input.dll.

DeerStealer exhibits advanced capabilities, including control flow obfuscation, virtual machine-based string decryption, and encrypted HTTPS communication with command-and-control (C2) servers. It fingerprints victim machines and packages stolen information into logs. It supports clipboard hijacking for over 14 cryptocurrency types and targets over 50 web browsers, as well as desktop applications like Discord, Telegram, FileZilla, and Steam.

The malware is available via a subscription model, with the Premium tier starting at $200 per month and the Professional tier at $3000. It offers features such as Hidden VNC for remote control, custom ClickFix scripts, and bypasses for Windows Defender and SmartScreen. Future expansions include MacOS support, AI integration, and automated crypto balance checking.

Advertisement

The sophisticated use of legitimate tools and obfuscation techniques necessitates enhanced vigilance, robust endpoint protection, and user education to prevent exploitation of system functionalities like the Windows Run Prompt.

Proactive measures are essential to detect and mitigate these complex threats before they compromise critical data.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories