Legion is a cloud-focused infostealer and spamming toolset associated with attacks against exposed web applications, SSH servers, and cloud/SaaS accounts. The provided content describes Legion as part of a cluster of Python-based cloud attack tools alongside AlienFox, GreenBot, Predator, and Androxgh0st-derived tooling, with functional overlap in credential harvesting and abuse of compromised services for spam operations. It is specifically referenced as a "Legion cloud infostealer" and a "Legion cloud spamming toolset," and one report assesses that the Legion maintainer likely adapted code from FBot. An updated version of Legion is described as adding features to compromise SSH servers and Amazon Web Services credentials associated with DynamoDB and CloudWatch. The content also notes that several Legion Stealer samples used hxxps://www.robertkalinkin.com/index.php to authenticate PayPal API requests, indicating overlap in PayPal account validation tradecraft seen in related tooling. Targeting is centered on cloud and web environments, especially AWS-linked credentials and exposed services. One mention also lists Legion among ransomware families for which AVG provides a decryptor, but the supplied content does not provide high-confidence technical detail to characterize that ransomware variant further.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
FBot has three functions dedicated to AWS account attacks. The first is an AWS API Key Generator, handled by function aws_generator, which generates a random AWS access key ID by appending 16 randomly selected alphabetic characters to the standard AKIA prefix. Then, it generates a secret key from 40 randomly selected alphabetic characters.
If these features were fully implemented, the attacker could use them to perform the following when they have valid AWS account credentials: Check for all email accounts in an AWS SES environment. Check send quotas. Create a new account, assign administrative privileges, and delete the old account.
The Hidden Config Scanner feature takes a URL as input and crafts an HTTP GET request to several PHP, Laravel, and AWS-related URIs where configuration values may be stored, including: _profiler/phpinfo config.js .env config/aws.yml .env.bak info.php aws.yml phpinfo aws/credentials phpinfo.php
If these features were fully implemented, the attacker could use them to perform the following when they have valid AWS account credentials: Check for all email accounts in an AWS SES environment. Check send quotas. Create a new account, assign administrative privileges, and delete the old account.
If these features were fully implemented, the attacker could use them to perform the following when they have valid AWS account credentials: Check for all email accounts in an AWS SES environment. Check send quotas. Create a new account, assign administrative privileges, and delete the old account.
If these features were fully implemented, the attacker could use them to perform the following when they have valid AWS account credentials: Check for all email accounts in an AWS SES environment. Check send quotas. Create a new account, assign administrative privileges, and delete the old account.
The response is parsed for keys and secrets related to the following services and the result is written to a text file: AWS ... Office365 ... Sendgrid ... Twilio ... Mailgun | FBot is primarily designed for actors to hijack cloud, SaaS, and web services. There is a secondary focus on obtaining accounts to conduct spamming attacks. Actors can use the credential harvesting features to obtain initial access, which they can sell to other parties.
Predator has features that can be used to attack many popular web services and technologies, including... Amazon Web Services (AWS) Simple Email Service (SES)... Twilio... Stripe... Telnyx... Predator’s web application attacks look for common weaknesses, misconfigurations or vulnerabilities...
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cloud infostealer with overlapping functionality to FBot, including scraping URLs for PHP configuration and use of similar PayPal validation infrastructure.
Ransomware family for which AVG provides a decryptor.
A cloud spamming and cloud-service attack toolset referenced as similar to Predator AI and sharing overlapping publicly available code.
Legion is a Python-based hack tool and credential stealer that targets cloud services, SSH servers, and web servers to harvest credentials and exfiltrate data via Telegram.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.