logo

Hackers Use OnionDrop Loader With DLL Sideloading to Deploy Multiple Infostealers

ID: 5c8dace2-9a81-55d3-a87c-f318d5f7411e

STIX ID: report--5c8dace2-9a81-55d3-a87c-f318d5f7411e

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Mayura Kathir

...
...

A high-tempo campaign is using a professionally engineered loader called OnionDrop — delivered via Adobe-signed executable DLL sideloading — to distribute multiple infostealers (LegionLoader, CGrabber, Vidar). The report documents a multi-stage unpack/decrypt pipeline (custom byte-pair decoding, Xpress Huffman, AES-256-CBC, Donut shellcode), evasion TTPs (NtCreateThreadEx, Thread Pool callback registration, API name obfuscation, GPU whitelist checks), YARA retro-hunting that found 645+ unique DLL samples, and provides IOCs (C2 gainmsg.com and numerous SHA256 hashes) and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.