Researchers exposed an active LegionLoader malware campaign, also tracked as Satacom, CurlyGate, and RobotDropper, that uses drive-by-download lures and short-lived redirect pages to push password-protected archives from file-sharing services such as Mega. The archives contain MSI installers that unpack and sideload a malicious obs.dll, which decrypts shellcode and a second-stage executable before using process hollowing into explorer.exe to continue execution. Analysis found heavy use of .monster domains, hard-coded command-and-control infrastructure, and tooling intended to download additional payloads, although some observed C2 servers were inactive during review.
The activity aligns with earlier Satacom operations that abused malicious or compromised websites and fake download buttons to distribute malware disguised as free or cracked software. In prior campaigns, the loader fetched follow-on payloads through DNS TXT lookups and PowerShell, then installed a fake Chromium-based "Google Drive" extension that targeted cryptocurrency users by stealing wallet data, manipulating transactions, bypassing 2FA, and suppressing transaction emails across Gmail, Hotmail, and Yahoo. The newer findings indicate the operators continue to rely on staged delivery, stealthy execution, and flexible payload retrieval, while defenders have been provided with hashes, URLs, file paths, registry artifacts, and YARA rules to detect the campaign.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On January 31, 2025, researchers detected 25 unique campaign URLs within a 12-hour period, indicating rapid infrastructure churn in the LegionLoader operation.
TEHTRIS says the observed LegionLoader campaign appears to have started on December 19, 2024, using drive-by-download lures and redirect pages to deliver malware.
Securelist states that the Satacom downloader, also known as LegionLoader, emerged in 2019 as a malware family.
Securelist reported on a Satacom campaign that used fake software downloads and process hollowing to install a malicious Chromium-based extension that targeted cryptocurrency users.
TEHTRIS published an analysis describing the active LegionLoader campaign, its delivery chain, malware stages, and associated indicators including hashes, URLs, artifacts, and YARA rules.
Securelist reported that telemetry in Q1 2023 showed the highest infection frequencies in Brazil, Algeria, Turkey, Vietnam, Indonesia, India, Egypt, and Mexico.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.