Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
New Case Study: Credit Union Boosts Threat Prevention & Detection with Cymulate
Learn More
New Research: Cymulate Research Labs Discovers Token Validation Flaw
Learn More
An Inside Look at the Technology Behind Cymulate
Learn More

PrivateLoader: The first step in many malware schemes

February 9, 2022

PrivateLoader is delivered through a network of websites that claim to provide "cracked" software, which is modified versions of popular legitimate applications that people commonly use. These websites are SEO optimized and usually appear at the top of search queries that contain keywords such as "crack" or "crack download" preceded by the software name. Visitors are lured into clicking a "Download Crack" or "Download Now" button to obtain an allegedly cracked version of the software. The JavaScript for the download button is retrieved from a remote server. After a few redirections, the final payload is served to the user as a password-protected compressed (.zip) archive which contains one of the malware payloads mentioned above.