Researchers detailed OnionDrop, a high-severity multi-stage malware loader being used to deliver information-stealing malware at scale, including LegionLoader (also called CurlyGate), CGrabber, and Vidar Stealer. The malware is described as unusually sophisticated for a commodity operation, with reporting from multiple security firms highlighting engineering and tradecraft more commonly associated with higher-end threat activity.
Analysis shows OnionDrop uses a layered infection chain and multiple stealth mechanisms to hinder detection and reverse engineering, including DLL sideloading, layered decoding and decryption, dynamic API resolution, anti-analysis checks, and shellcode execution through Windows Thread Pool callbacks. Defenders were provided with threat-hunting material including an associated URL indicator and multiple SHA-256 hashes to support detection of the loader and related payloads.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Gurucul published threat research on OnionDrop, detailing its use in distributing LegionLoader, CGrabber, and Vidar Stealer and providing one URL indicator plus nine SHA-256 hashes for detection and hunting.
Cyderes published an analysis describing OnionDrop as a sophisticated multi-stage malware loader used to deliver information-stealing payloads and employing advanced evasion and execution techniques.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.