Legion Loader is a Windows malware loader and dropper used to deliver a range of follow-on payloads, particularly information stealers. It has been observed distributing malware such as Raccoon Stealer and is associated with broader malware delivery ecosystems rather than a single exclusive intrusion set. The malware has appeared in pay-per-install distribution operations, spam-delivered downloader chains, SEO-poisoning campaigns, and fake CAPTCHA or paste-and-run social-engineering flows.
A notable Legion Loader delivery pattern uses a small downloader stub that retrieves an encrypted payload from legitimate cloud-storage or file-hosting services, decrypts it on the victim system, and executes it only in memory. This chain commonly employs heavy obfuscation, anti-disassembly measures, anti-debugging logic, dynamic API resolution, and sandbox-evasion checks. Some variants inject decrypted shellcode into a suspended child process and can defer payload retrieval until after reboot by establishing autorun persistence. The use of reputable cloud services as payload hosts helps the operation blend into normal traffic and complicates blocking.
Legion Loader has also been delivered through MSI-based installers and batch-script execution, including campaigns driven by black-hat SEO and fake software-download pages. In 2025 it was repeatedly associated with fake CAPTCHA and ClickFix-style lures that instruct victims to paste and run commands through the Windows Run dialog, effectively turning user interaction into the execution mechanism. It has additionally been seen in large traffic-distribution systems that filter victims by geography, device type, and anti-bot checks before routing qualified users to Legion Loader landing infrastructure.
Operationally, Legion Loader functions as an initial-stage malware component that enables downstream compromise by fetching and launching additional payloads. Its role in multi-stage delivery chains, memory-only execution patterns, and broad use across malvertising, spam, PPI, and social-engineering ecosystems make it a flexible malware delivery platform rather than a final objective payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
a small VBS script ... is created with the following content: Set W = CreateObject("WScript.Shell") Set C = W.Exec ("C:\Users\User\subfolder1\filename1.exe")
In most scenarios, once users interact with the Fix or Verify button in the lure, the button will covertly copy an obfuscated PowerShell command to the clipboard and present the user with “verification steps.”
...telling the victim to press Win+R and paste a command that installs an MSI as “Klio Verfair Tools” and drops Legion Loader.
a small VBS script ( C:\{USERPROFILEPATH}\subfolder1\filename1.vbs ) is created with the following content: Set W = CreateObject("WScript.Shell") Set C = W.Exec ("C:\Users\User\subfolder1\filename1.exe")
After resolving the addresses of the API functions, the dropper launches another process of itself in a suspended state. The malware unmaps its image from the image base of this child process, maps the msvbvm60.dll library there (at 0x400000), allocates memory in the child process, copies the decrypted shellcode into the allocated memory, and transfers execution there.
the files are encrypted. They are only decrypted on the victim machine, using “rotating XOR” decryption and a rather long key, which ranges from 200 to 1000 bytes in length and is hardcoded in the downloader stub.
The dropper dynamically resolves API functions... Function names are stored in the code right after calls to procedures that have no returns.
The payload is sometimes disguised and made to superficially resemble a picture in a popular image format.
After resolving the addresses of the API functions, the dropper launches another process of itself in a suspended state. The malware unmaps its image from the image base of this child process, maps the msvbvm60.dll library there (at 0x400000), allocates memory in the child process, copies the decrypted shellcode into the allocated memory, and transfers execution there.
“The delivery mechanism for Legion Loader... leverages an MSI installer to deploy the malware via a batch script.”
the shellcode also includes a host of techniques to check if it’s running in a sandbox, and refuse to run if the answer is positive. The researched sample in particular checked the number of top level windows; If this number is less than 12, the dropper silently exits.
The decrypted payload is manually loaded to its image base address that is extracted from the PE header of the payload. The dropper then creates a new thread to run the payload without creating a separate process.
The shellcode is also obfuscated (because of course it is), making IDA unable to automatically analyze it. It also contains some anti-debugging tricks... the malware hides the current thread from the debugger... The dropper prevents the debugger from attaching to the running process by hooking the DbgUiRemoteBreakin function... It also replaces the DbgBreakPoint function body with a NOP operation.
the shellcode also includes a host of techniques to check if it’s running in a sandbox, and refuse to run if the answer is positive. The researched sample in particular checked the number of top level windows; If this number is less than 12, the dropper silently exits.
The shellcode is also obfuscated (because of course it is), making IDA unable to automatically analyze it. It also contains some anti-debugging tricks... the malware hides the current thread from the debugger... The dropper prevents the debugger from attaching to the running process by hooking the DbgUiRemoteBreakin function... It also replaces the DbgBreakPoint function body with a NOP operation.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware loader delivered via FakeCaptcha/TDS infrastructure. Victims are routed to a fake CAPTCHA page that uses clipboard hijacking and social engineering to execute a command that installs an MSI and drops Legion Loader.
A loader delivered via paste-and-run campaigns.
Dropper/loader used to deliver a variety of different payloads.
Malware loader delivered via SEO poisoning; uses an MSI installer and a batch script to deploy the payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.