Skip to content
Malware family

XTinyLoader

XTinyLoader is a malware loader observed in StealC-linked intrusion activity.

Profile source: Mallory opens in a new tab

XTinyLoader

Family profile

XTinyLoader is a malware loader observed in StealC-linked intrusion activity. Multiple cited investigations by Proofpoint and IBM X-Force identified XTinyLoader among secondary payloads delivered through StealC infections, alongside other malware such as Amadey, AsyncRAT, RedLine Stealer, Vidar, and XMRig. In a specifically noted infection chain, StealC downloaded XTinyLoader, which subsequently downloaded and delivered LockBit Black ransomware. Based on the provided content, XTinyLoader’s confirmed role is as a follow-on downloader/loader used after initial compromise by StealC to retrieve additional malicious payloads, including ransomware. The content does not provide further technical details on XTinyLoader’s internal functionality, persistence, or standalone infection vector beyond its observed delivery via StealC.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 19, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
4 IP / 0 hostnames

Leading locations

  • DE3
  • NL1

Leading providers

  • FEMO IT SOLUTIONS LIMITED3
  • Omegatech LTD1

Infrastructure traits

  • Hosting 4

Samples

Recent associated samples

MITRE ATT&CK

XTinyLoader in ATT&CK

3 distinct techniques

Reporting

Research mentioning XTinyLoader

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.