Last seven days
- First activity
- Aug 17, 2026
- Last activity
- Aug 17, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Legion is a cloud-focused infostealer and spamming toolset associated with attacks against exposed web applications, SSH servers, and cloud/SaaS accounts.
Profile source: Mallory opens in a new tabLegion
Legion is a cloud-focused infostealer and spamming toolset associated with attacks against exposed web applications, SSH servers, and cloud/SaaS accounts. The provided content describes Legion as part of a cluster of Python-based cloud attack tools alongside AlienFox, GreenBot, Predator, and Androxgh0st-derived tooling, with functional overlap in credential harvesting and abuse of compromised services for spam operations. It is specifically referenced as a "Legion cloud infostealer" and a "Legion cloud spamming toolset," and one report assesses that the Legion maintainer likely adapted code from FBot. An updated version of Legion is described as adding features to compromise SSH servers and Amazon Web Services credentials associated with DynamoDB and CloudWatch. The content also notes that several Legion Stealer samples used hxxps://www.robertkalinkin.com/index.php to authenticate PayPal API requests, indicating overlap in PayPal account validation tradecraft seen in related tooling. Targeting is centered on cloud and web environments, especially AWS-linked credentials and exposed services. One mention also lists Legion among ransomware families for which AVG provides a decryptor, but the supplied content does not provide high-confidence technical detail to characterize that ransomware variant further.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.