Skip to main content

Threats Tagged 'legionloader'

View all threats tagged with 'legionloader'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: legionloader

Threats Tagged 'legionloader'

Click on any threat for detailed analysis and mitigation recommendations

LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

Join the discussion

A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

Join the discussion

WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: legionloader
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses