Threat actors increasingly used small, heavily obfuscated droppers to retrieve encrypted malware payloads from trusted cloud storage platforms including Google Drive, OneDrive, Dropbox, and SharePoint, then decrypt and execute them only in memory. Check Point Research linked the technique to Legion Loader and multiple other malware families such as NanoCore, LokiBot, Remcos, and Pony Stealer, identifying roughly 10,000 samples and about 800 new samples per week; Google Drive accounted for 72% of observed payload downloads.
The droppers were commonly distributed through spam campaigns carrying ISO attachments and used anti-debugging, sandbox evasion, and optional registry autorun persistence to delay payload retrieval until after reboot. Researchers said the downloaded files were typically stored in encrypted form using rotating-XOR with long hardcoded keys, often with names containing _encrypted_, and were never written to disk in decrypted form, making retrospective forensic analysis more difficult even as well-instrumented sandboxes could still reveal the full infection chain.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Check Point Research published analysis of a malware delivery method in which droppers fetch encrypted payloads from cloud storage services such as Google Drive, OneDrive, Dropbox, and SharePoint, decrypt them on the victim machine, and execute them only in memory. The research linked the technique to Legion Loader and other malware families including NanoCore, LokiBot, Remcos, and Pony Stealer, and reported roughly 10,000 samples and about 800 new samples per week.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.