Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 0 hostnames
XTinyLoader is a malware loader observed in StealC-linked intrusion activity.
Profile source: Mallory opens in a new tabXTinyLoader
XTinyLoader is a malware loader observed in StealC-linked intrusion activity. Multiple cited investigations by Proofpoint and IBM X-Force identified XTinyLoader among secondary payloads delivered through StealC infections, alongside other malware such as Amadey, AsyncRAT, RedLine Stealer, Vidar, and XMRig. In a specifically noted infection chain, StealC downloaded XTinyLoader, which subsequently downloaded and delivered LockBit Black ransomware. Based on the provided content, XTinyLoader’s confirmed role is as a follow-on downloader/loader used after initial compromise by StealC to retrieve additional malicious payloads, including ransomware. The content does not provide further technical details on XTinyLoader’s internal functionality, persistence, or standalone infection vector beyond its observed delivery via StealC.
C2 tracking
Derp observations, rolling seven-day window
Samples
137c0ebdcc26e8ec716854e2096d54cc8f0fc1bd320400c868084be3acb493be 20422fd929041306aaf2a2211868a24879fe716c74b51b28ace932f2175c2494 59b3cd435ab9f10a5c124df27c75a3ce779d709fdc63ea5bcbee5f7f5fa583fe 9d712692a206c186c65e1748c23cb0613e54fdf8edde37b40ee2eb4145f5782f b55b53bb519f4f21549bfb3dc434259ddcfa082ea25d78bba8b8776d1009238c c66d61d772462b89a32d476d82f16ae12442064ea505d50e214a4b964d6d328b 0446aa639f5d048a5509a9b66466326f666fdf5a8bdeb150ffd812a9c588a4f4 0e9afeeac20392cbc350e18b90a0a445d535a04c1b5c3e8defe8a5f57dd07864 3f83dade3913b67e871ea278485a188b72e50deda0267f3b30555f8cd2b9a44d b5a211c440628f225bd8268c466305f3012096ec84f5821ef8045ece50e3c1bc MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.