-
A seller known as “Special” is marketing a private Windows loader built to run malware quietly.
-
The tool reportedly hides from antivirus programs and restarts itself if someone tries to remove it.
-
Researchers say the tricks are common in real malware, but no one has proven this tool actually works.

A hacker is selling a new tool that helps other criminals sneak harmful programs onto Windows computers. The seller goes by the name “Special.” According to Dark Web Informer, this person is looking for partners among malware sellers and ransomware gangs.
The tool works on Windows 10 and Windows 11. The seller markets it as a native Windows product, built to blend in and avoid detection.
The Tool Claims Deep Access and Strong Persistence
The seller says the loader can stay on a computer long after someone tries to remove it. It reportedly uses several startup tricks at once. If one method gets deleted, the tool rebuilds it on its own. That means a single cleanup attempt may not be enough to fully remove it.
The loader also claims to run harmful files straight from a computer’s memory. This includes EXE and DLL files, plus shellcode, batch files, and JavaScript. Running code this way can make it harder for security software to catch, since fewer files get written to the hard drive.
Beyond that, the tool reportedly gives an attacker remote control over infected machines. It can open, edit, or delete files. It can also inspect running programs and download new ones. The buyer can even set how often the tool “checks in” with its controller.
The loader is also said to gather details about each infected computer. This includes hardware IDs, IP addresses, computer names, account names, and domain information. It reportedly checks whether the user has administrator rights too. That kind of data helps an attacker plan a bigger attack later.
Seller Lists Several Tricks to Dodge Security Software
According to the ad, the tool can spot which antivirus program is running on a computer. It then reportedly sends stolen data back to its controller using encrypted web traffic. That traffic is designed to look like normal internet activity.
The seller also claims the loader routes its traffic through extra servers. This step is meant to make the connection harder to block or trace. Other listed features include custom system commands, hidden text inside the code, and network traffic disguised to look ordinary.
The seller also suggests two ways to spread the tool. One method hides it inside a real, working program. The other bundles it with a legitimate installer. In both cases, the real software keeps working normally. Meanwhile, the hidden tool runs quietly in the background.
Many of these tricks already show up in real attacks. MITRE ATT&CK lists process injection as a known method attackers use to hide code inside normal programs. That alone does not confirm this specific tool works as advertised, though. Microsoft’s documentation also warns that installing apps from outside its official store raises security risks.
A recent Microsoft investigation found malware using similar tricks, including scheduled tasks and hidden startup entries. Similar backdoor campaigns have also targeted other platforms, including macOS, where North Korean-linked hackers have used malicious backdoors against an India-based IT firm. That shows the methods in this ad are technically possible, even if this exact tool remains unverified.
No Proof Backs Up the Seller’s Claims
The seller describes the loader as fully hidden from antivirus tools. As proof, they point to a scan result showing zero out of fourteen security programs caught it. The scan reportedly came from a site called euro-scan.
However, nobody outside the seller has confirmed that result. A single scan, especially one the seller supplied, does not prove a tool is invisible to every antivirus program. Detection results can change between software versions, updates, and even individual copies of the same malware. A clean scan today does not guarantee the same result tomorrow.
Dark Web Informer also reported that the seller is building a new feature. This one would let the tool automatically change its own code to dodge detection. The seller reportedly plans to offer custom versions aimed at business targets too.
Right now, this loader should be treated as an unproven ad on an underground market. Its claimed features may be real. They may also be exaggerated or entirely false. There is no independent evidence confirming how the tool actually performs.
What This Means Going Forward
Security teams should treat this listing as a warning sign, not a confirmed threat. Businesses can lower their risk by only installing software from trusted, official sources. IT teams should also watch for unfamiliar startup entries and unexpected outbound web traffic.
Keeping antivirus tools updated matters too, even though detection is never guaranteed. Regularly checking scheduled tasks and startup folders can catch hidden persistence early. Security teams should also monitor for encrypted traffic patterns that do not match normal business activity.
For now, no confirmed victims or real-world use of this loader have surfaced. Researchers will likely keep watching to see if that changes.