LegionLoader Abusing Chrome Extensions To Deliver Infostealer Malware
ID: 381487d7-1417-5ceb-8acf-c32828122071
STIX ID: report--381487d7-1417-5ceb-8acf-c32828122071
Feed Name: GBHackers
LegionLoader is a sophisticated C/C++ downloader that delivers stealers and malicious Chrome extensions, uses MSI-side loading and DLL sideloading via steamerrorreporter64.exe for persistence, employs multiple layers of obfuscation (Base64, RC4, XTEA, CRC32-hashed APIs), injects payloads via process hollowing into explorer.exe, and communicates with hardcoded C2 servers to retrieve and execute additional payloads; recent activity since August 2024 includes distribution of LummaC2, Rhadamanthys, and StealC hosted on services like MEGA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
