Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OnionDrop Campaign Delivers LegionLoader via gainmsg C2

OnionDrop Campaign Delivers LegionLoader via gainmsg C2

Posted on June 17, 2026 By CWS

In the cybersecurity realm, a newly identified loader campaign is generating significant concern. This campaign, leveraging a sophisticated multi-stage loader known as OnionDrop, is actively distributing harmful payloads such as the infamous LegionLoader to numerous targets.

Technical Sophistication and Persistent Threat

Since at least February 2026, OnionDrop has been operational, with more than 645 unique malicious DLL samples identified over approximately 80 days. As of the latest reports, this campaign remains active, posing a persistent threat that demands immediate defensive measures from security teams.

OnionDrop’s distinctiveness lies not only in its payload delivery but also in the remarkable technical sophistication embodied within the loader. Researchers at Cyderes, through their Howler Cell Threat Research Team, have documented OnionDrop as a critical component within a larger campaign framework, following previous operations like CGrabber Infostealer and Direct-sys Loader.

Advanced Evasion Techniques

The OnionDrop campaign’s danger is amplified by its payload-agnostic design, confirmed to be delivering multiple infostealers like LegionLoader (also known as CurlyGate), CGrabber, and Vidar Stealer. This reflects a highly organized threat actor capable of running parallel infostealer operations without losing momentum.

Security professionals are advised to monitor indicators of compromise linked to this campaign, prevent connections to the known C2 domain, and update endpoint detection rules to flag DLL sideloading activities involving Adobe-signed executables.

Unpacking the Attack Chain

The attack initiates with a ZIP archive containing an Adobe-signed executable, originally named AcroBroker.exe, alongside malicious DLLs named sqlite.dll and codecstore384d.dll. A decoy file named data.bin, filled with random bytes, is also included to increase the archive’s size and hinder analysis.

Upon execution of the Adobe file, it sideloads sqlite.dll, which proceeds to load the primary malicious DLL. OnionDrop then undergoes four unpacking stages, employing techniques like custom byte-pair decoding and AES-256-CBC decryption, engineered to thwart both automated and manual analysis.

The final payload, LegionLoader, decrypts its configuration using RC4 and communicates with its command-and-control server hosted on gainmsg[.]com/nfront[.]php, facilitating data exfiltration and command execution.

Implications and Future Considerations

OnionDrop’s anti-analysis measures distinguish it from standard commodity loaders. By employing methods such as stack-string construction and API hammering, OnionDrop obscures its malicious activities, complicating detection efforts. Additionally, it verifies the system’s GPU against a list of legitimate strings, halting execution in virtual or sandbox environments.

This campaign’s sophisticated evasion techniques, including the final shellcode execution via Windows Thread Pool callback abuse, underscore the long-term strategic investment by the threat actors. Security teams must remain vigilant and proactive in adapting to such evolving threats.

Cyber Security News Tags:C2 infrastructure, command-and-control, cyber threat, Cybersecurity, Cyderes, DLL Sideloading, gainmsg, InfoStealer, LegionLoader, Malware, malware evasion, OnionDrop, Payloads, Security, Threat Actors

Post navigation

Previous Post: GitGuardian Enhances Developer Security with New Endpoint Protection
Next Post: Cyberattack Uses Fake CAPTCHA to Deploy Malware

Related Posts

Malvertising Campaign Exploits ChatGPT for Malware Delivery Malvertising Campaign Exploits ChatGPT for Malware Delivery Cyber Security News
Monsta web-based FTP Remote Code Execution Vulnerability Exploited Monsta web-based FTP Remote Code Execution Vulnerability Exploited Cyber Security News
Critical Exim GnuTLS Flaw Exposes Servers to Attacks Critical Exim GnuTLS Flaw Exposes Servers to Attacks Cyber Security News
Impacket Tool in Kali Repo Upgraded With New Attack Paths and Relay Tricks Impacket Tool in Kali Repo Upgraded With New Attack Paths and Relay Tricks Cyber Security News
OpenAI Introduces AI Safety Bug Bounty Program OpenAI Introduces AI Safety Bug Bounty Program Cyber Security News
Hackers Allegedly Claim Breach of Mercedes-Benz USA Legal and Customer Data Hackers Allegedly Claim Breach of Mercedes-Benz USA Legal and Customer Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ghostwriter Hackers Target Gmail with Phishing Emails
  • Cyberattack Uses Fake CAPTCHA to Deploy Malware
  • OnionDrop Campaign Delivers LegionLoader via gainmsg C2
  • GitGuardian Enhances Developer Security with New Endpoint Protection
  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ghostwriter Hackers Target Gmail with Phishing Emails
  • Cyberattack Uses Fake CAPTCHA to Deploy Malware
  • OnionDrop Campaign Delivers LegionLoader via gainmsg C2
  • GitGuardian Enhances Developer Security with New Endpoint Protection
  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark