logo

OnionDrop Loader Uses Nation-State-Grade Evasion to Deliver LegionLoader, CGrabber, and Vidar

ID: 7e53f3f9-d743-5271-a2c7-fc9d35152c2f

STIX ID: report--7e53f3f9-d743-5271-a2c7-fc9d35152c2f

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Varshini

...
...

OnionDrop is a sophisticated, payload-agnostic loader observed between February and May 2026 that uses layered evasion techniques (dynamic API resolution, stack-string construction, custom byte-pair encoding, Xpress Huffman decompression, rotating decryption keys, and Donut shellcode executed via the Windows Thread Pool) to drop infostealers at scale. The campaign distributes malicious sqlite.dll dependencies via ZIP archives containing an Adobe-signed executable and large decoy files, has produced 645+ DLL samples, and commonly delivers LegionLoader and Vidar with active C2 infrastructure (gainmsg.com), indicating an ongoing, high-tempo criminal operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.