Legion Loader is a malware dropper/loader observed delivering a variety of different payloads. Red Canary reported it as one of the threats delivered through paste-and-run social-engineering activity in 2025, where victims are tricked into pasting and executing malicious commands that download additional malware. Red Canary also noted Legion Loader as precursor-tracked activity that would have entered its July 2025 top 10 prevalence list if remediated later, and described it as a dropper that delivers multiple payload types. Separately, Zscaler ThreatLabz reported Legion Loader being distributed through black-hat SEO poisoning around AI-related keywords. In that campaign, users were redirected to phishing pages, and Legion Loader was delivered via an MSI installer that used a batch script to deploy the malware. High-confidence infection vectors mentioned in the content are paste-and-run lures and SEO-poisoning-driven fake download/phishing pages. No specific threat actor attribution, industry targeting, or concrete IOC values for Legion Loader itself were provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"The NSIS installer is then used to execute an AutoIt script..."; "...deploy the malware via a batch script."
In most scenarios, once users interact with the Fix or Verify button in the lure, the button will covertly copy an obfuscated PowerShell command to the clipboard and present the user with “verification steps.”
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader delivered via paste-and-run campaigns.
Dropper/loader used to deliver a variety of different payloads.
Malware loader delivered via SEO poisoning; uses an MSI installer and a batch script to deploy the payload.
Loader distributed via SEO poisoning campaigns; delivered using an MSI installer that executes a batch script to deploy the malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.