logo

LegionLoader Abusing Chrome Extensions To Deliver Infostealer Malware

ID: 381487d7-1417-5ceb-8acf-c32828122071

STIX ID: report--381487d7-1417-5ceb-8acf-c32828122071

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2025-01-03

Date Updated: 2026-04-22

Author: Balaji

...
...

LegionLoader is a sophisticated C/C++ downloader that delivers stealers and malicious Chrome extensions, uses MSI-side loading and DLL sideloading via steamerrorreporter64.exe for persistence, employs multiple layers of obfuscation (Base64, RC4, XTEA, CRC32-hashed APIs), injects payloads via process hollowing into explorer.exe, and communicates with hardcoded C2 servers to retrieve and execute additional payloads; recent activity since August 2024 includes distribution of LummaC2, Rhadamanthys, and StealC hosted on services like MEGA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.