XTinyLoader is a malware loader observed in StealC-linked intrusion activity. Multiple cited investigations by Proofpoint and IBM X-Force identified XTinyLoader among secondary payloads delivered through StealC infections, alongside other malware such as Amadey, AsyncRAT, RedLine Stealer, Vidar, and XMRig. In a specifically noted infection chain, StealC downloaded XTinyLoader, which subsequently downloaded and delivered LockBit Black ransomware. Based on the provided content, XTinyLoader’s confirmed role is as a follow-on downloader/loader used after initial compromise by StealC to retrieve additional malicious payloads, including ransomware. The content does not provide further technical details on XTinyLoader’s internal functionality, persistence, or standalone infection vector beyond its observed delivery via StealC.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, it has an optional loader functionality that can be used to retrieve additional payloads such as infostealers, remote access trojans (RATs) and ransomware... In one case, XTinyLoader was installed, which subsequently downloaded LockBit Black ransomware.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader observed in the campaign that subsequently downloaded LockBit Black ransomware.
XTinyLoader is listed as a malware family delivered in StealC-linked activity.
XTinyLoader is a loader malware observed being downloaded by StealC and then used to deliver a LockBit Black ransomware payload.
A loader observed as an intermediate payload in StealC infections, including delivery of LockBit Black ransomware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.