Last seven days
- First activity
- Jul 19, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2
- Host form
- 4 IP / 0 hostnames
XTinyLoader is a malware loader observed in StealC-linked intrusion activity.
Profile source: Mallory opens in a new tabXTinyLoader
XTinyLoader is a malware loader observed in StealC-linked intrusion activity. Multiple cited investigations by Proofpoint and IBM X-Force identified XTinyLoader among secondary payloads delivered through StealC infections, alongside other malware such as Amadey, AsyncRAT, RedLine Stealer, Vidar, and XMRig. In a specifically noted infection chain, StealC downloaded XTinyLoader, which subsequently downloaded and delivered LockBit Black ransomware. Based on the provided content, XTinyLoader’s confirmed role is as a follow-on downloader/loader used after initial compromise by StealC to retrieve additional malicious payloads, including ransomware. The content does not provide further technical details on XTinyLoader’s internal functionality, persistence, or standalone infection vector beyond its observed delivery via StealC.
C2 tracking
Derp observations, rolling seven-day window
Samples
0446aa639f5d048a5509a9b66466326f666fdf5a8bdeb150ffd812a9c588a4f4 3f83dade3913b67e871ea278485a188b72e50deda0267f3b30555f8cd2b9a44d 546069ffcf313838f3ac6b3e53b75b5251d7a54bb26e0098469c7380cf4c3f87 62c425f43d0a39c14ad94ae6c117e3aee398a4a3e617b01dc7602e8c39a93840 b5a211c440628f225bd8268c466305f3012096ec84f5821ef8045ece50e3c1bc cc6bca67fc61eb4fd0e9d8e6cbf058f4f21aff8ae0824fc5557c77cad626039c 0e9afeeac20392cbc350e18b90a0a445d535a04c1b5c3e8defe8a5f57dd07864 f690fc36d2e6c795b0310cb9af23c0283a8c1ab39322ea8bb6e4f69290c2f14a MITRE ATT&CK
Reporting
In one case, XTinyLoader was installed, which subsequently downloaded LockBit Black ransomware.
Proofpoint and IBM X-Force researchers observed StealC-linked activity delivering malware families, including the following: ... XTinyLoader ...
In one case, StealC downloaded XTinyLoader, which then downloaded a LockBit Black ransomware payload.
One notable example is a StealC client downloading XTinyLoader, which, in turn, downloaded a LockBit Black ransomware payload.
One notable example is a StealC client downloading XTinyLoader, which, in turn, downloaded a LockBit Black ransomware payload.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.