OnionDrop Loader Campaign Delivers LegionLoader and Infostealers at Scale
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A new loader campaign, OnionDrop, is actively delivering malicious payloads, including LegionLoader and multiple infostealers, to a wide range of victims. Researchers identified over 645 unique DLL samples associated with OnionDrop between February 28 and May 20, 2026. The campaign employs sophisticated DLL sideloading techniques to evade detection and has been operational since at least early 2026. Current deliveries remain active, indicating a significant ongoing threat to various systems. The scale of the operation and its advanced evasion methods raise serious concerns within the cybersecurity community.
Key Points: • OnionDrop loader is delivering LegionLoader and multiple infostealers. • Over 645 unique DLL samples linked to OnionDrop were identified in recent months. • The campaign utilizes DLL sideloading techniques to evade detection.