ThreatCluster

OnionDrop Loader Campaign Delivers LegionLoader and Infostealers at Scale

First seen 17 Jun 2026, 02:44 UTC GbhackersCybersecuritynews 73% similarity 68

Article Content

Browse articles
ThreatCluster

A new loader campaign, OnionDrop, is actively delivering malicious payloads, including LegionLoader and multiple infostealers, to a wide range of victims. Researchers identified over 645 unique DLL samples associated with OnionDrop between February 28 and May 20, 2026. The campaign employs sophisticated DLL sideloading techniques to evade detection and has been operational since at least early 2026. Current deliveries remain active, indicating a significant ongoing threat to various systems. The scale of the operation and its advanced evasion methods raise serious concerns within the cybersecurity community.

Key Points: • OnionDrop loader is delivering LegionLoader and multiple infostealers. • Over 645 unique DLL samples linked to OnionDrop were identified in recent months. • The campaign utilizes DLL sideloading techniques to evade detection.

ThreatCluster AI How this analysis works

Timeline

2026-02-28
OnionDrop campaign identified
Threat researchers began tracking the OnionDrop loader's activities and its payload deliveries.
Gbhackers
2026-05-20
645 unique DLL samples discovered
YARA retro-hunting uncovered a significant number of unique DLL samples associated with OnionDrop.
Gbhackers
2026-06-17
OnionDrop loader campaign reported
Cybersecuritynews published details on the ongoing OnionDrop loader campaign and its impact.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story