OnionDrop Loader Uses Nation-State-Grade Evasion to Deliver LegionLoader, CGrabber, and Vidar
ID: 7e53f3f9-d743-5271-a2c7-fc9d35152c2f
STIX ID: report--7e53f3f9-d743-5271-a2c7-fc9d35152c2f
Feed Name: Cyber Press
OnionDrop is a sophisticated, payload-agnostic loader observed between February and May 2026 that uses layered evasion techniques (dynamic API resolution, stack-string construction, custom byte-pair encoding, Xpress Huffman decompression, rotating decryption keys, and Donut shellcode executed via the Windows Thread Pool) to drop infostealers at scale. The campaign distributes malicious sqlite.dll dependencies via ZIP archives containing an Adobe-signed executable and large decoy files, has produced 645+ DLL samples, and commonly delivers LegionLoader and Vidar with active C2 infrastructure (gainmsg.com), indicating an ongoing, high-tempo criminal operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
