Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is distributed via ClickFix tactics using fake Cloudflare CAPTCHA pages. It uses two main methods: malicious URLs on Korea's Newlywed Hope Town Namu Wiki page and spear phishing emails targeting companies with fake internal account issuance instructions. Victims are tricked into running PowerShell commands that download and execute LegionLoader. The malware decrypts payloads, checks the environment, and runs backdoor malware capable of executing various payload types. It also steals Chrome browser credentials and profile data based on commands from its command-and-control server.
AI Analysis
Technical Summary
LegionLoader malware is distributed through social engineering involving fake CAPTCHA pages that prompt users to execute PowerShell commands. Distribution occurs via malicious URLs on a Korean wiki page and spear phishing emails impersonating internal business communications. Upon execution, LegionLoader decrypts encrypted shellcode and PE files, performs environment checks including display device and ASN verification, then deploys backdoor malware capable of running PE files, shellcode, PowerShell scripts, and MSI files. It also exfiltrates Chrome browser credentials and profile information as directed by its C2 server.
Potential Impact
Successful infection results in a persistent backdoor on the victim system, enabling execution of arbitrary payloads including executables, scripts, and shellcode. Additionally, the malware steals sensitive browser credentials and profile data, potentially compromising user accounts and privacy.
Mitigation Recommendations
No official patches or fixes are available as this is malware distributed via social engineering. Mitigation focuses on user awareness to avoid clicking suspicious links and executing unexpected PowerShell commands. Organizations should educate users about spear phishing tactics and verify unexpected internal communications. Endpoint detection and response solutions should be employed to detect and block execution of suspicious PowerShell commands and known LegionLoader indicators.
Indicators of Compromise
- domain: dallasbackstage.com
- domain: gemscocl.com
- hash: 0128a4b78aab83796042118ecb3e46e0
- hash: 27745ec8bde201e771e3f4069e887cad
- hash: 685b6822b0c66f4f18496eb6ce24f984
- hash: 8467ca57bdf6e6e94ca4e1484628b1aa
- hash: c4debc1b25ab67f094676ddc3195fa41
Beware of the LegionLoader malware being distributed via the ClickFix method
Description
LegionLoader malware is distributed via ClickFix tactics using fake Cloudflare CAPTCHA pages. It uses two main methods: malicious URLs on Korea's Newlywed Hope Town Namu Wiki page and spear phishing emails targeting companies with fake internal account issuance instructions. Victims are tricked into running PowerShell commands that download and execute LegionLoader. The malware decrypts payloads, checks the environment, and runs backdoor malware capable of executing various payload types. It also steals Chrome browser credentials and profile data based on commands from its command-and-control server.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LegionLoader malware is distributed through social engineering involving fake CAPTCHA pages that prompt users to execute PowerShell commands. Distribution occurs via malicious URLs on a Korean wiki page and spear phishing emails impersonating internal business communications. Upon execution, LegionLoader decrypts encrypted shellcode and PE files, performs environment checks including display device and ASN verification, then deploys backdoor malware capable of running PE files, shellcode, PowerShell scripts, and MSI files. It also exfiltrates Chrome browser credentials and profile information as directed by its C2 server.
Potential Impact
Successful infection results in a persistent backdoor on the victim system, enabling execution of arbitrary payloads including executables, scripts, and shellcode. Additionally, the malware steals sensitive browser credentials and profile data, potentially compromising user accounts and privacy.
Defensive Guidance
No official patches or fixes are available as this is malware distributed via social engineering. Mitigation focuses on user awareness to avoid clicking suspicious links and executing unexpected PowerShell commands. Organizations should educate users about spear phishing tactics and verify unexpected internal communications. Endpoint detection and response solutions should be employed to detect and block execution of suspicious PowerShell commands and known LegionLoader indicators.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://asec.ahnlab.com/en/95374/"]
- Pulse Id
- 6aa3fef84a7f54f4ae325151
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaindallasbackstage.com | — | |
domaingemscocl.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0128a4b78aab83796042118ecb3e46e0 | — | |
hash27745ec8bde201e771e3f4069e887cad | — | |
hash685b6822b0c66f4f18496eb6ce24f984 | — | |
hash8467ca57bdf6e6e94ca4e1484628b1aa | — | |
hashc4debc1b25ab67f094676ddc3195fa41 | — |
Threat ID: 6aa410ea91cc7f384847d6ba
Added to database: 09/11/2026, 14:32:10 UTC
Last enriched: 09/11/2026, 14:48:47 UTC
Last updated: 09/11/2026, 16:17:50 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.