PULSE NAME
Don't Get Caught in the Headlights - DeerStealer Analysis
WHITE PetrP.73 2025-06-13 Modified: 2025-06-13
52
IOCs
HIGH VOLUME
In May 2025, threat actors increasingly attempted to download and execute a sophisticated malware known as HijackLoader, often using DeerStealer—an information-stealer marketed on dark-web forums by the user "LuciferXfiles"—as the final payload. The primary access method observed in these attack chains is called ClickFix, which exploits users by redirecting them to phishing pages prompting the execution of malicious commands in the Windows Run Prompt. The initial sequence involves loading an unsigned version of a legitimate DLL named "cmdres.dll," which has been manipulated to facilitate the execution of HijackLoader.
Indicators of Compromise (1 / 52 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 45592b1d7091d22706da0d64010f54187b5a85dd SHA1 of 3a03afc1313854359603522e0792f6a8f9153519eac645cf5811824d936cfbc7 2025-06-13