Last seven days
- First activity
- Sep 23, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 0 hostnames
XTinyLoader is a malware loader observed in StealC-linked intrusion activity.
Profile source: Mallory opens in a new tabXTinyLoader
XTinyLoader is a malware loader observed in StealC-linked intrusion activity. Multiple cited investigations by Proofpoint and IBM X-Force identified XTinyLoader among secondary payloads delivered through StealC infections, alongside other malware such as Amadey, AsyncRAT, RedLine Stealer, Vidar, and XMRig. In a specifically noted infection chain, StealC downloaded XTinyLoader, which subsequently downloaded and delivered LockBit Black ransomware. Based on the provided content, XTinyLoader’s confirmed role is as a follow-on downloader/loader used after initial compromise by StealC to retrieve additional malicious payloads, including ransomware. The content does not provide further technical details on XTinyLoader’s internal functionality, persistence, or standalone infection vector beyond its observed delivery via StealC.
C2 tracking
Derp observations, rolling seven-day window
Samples
3cea9df086d111a71c24822aa626380105347dd6d458ae7971557684bf12e097 5fb09f2cb96deeba595a4b58833406d2f00c6a1e56affc3d62655764bae7977c 6d73959dca75ec27ec3590f266f00422f3af4cf12e813e841916a2cc0d9bf9ae d72dcfdb13bcedc8115a7e0cec507d246e03285090bc3b802c606274fbbd9ce3 ea05197e0c3bfb7ca461146bcfba417834b97a96d2a24397d745fe0f487e5d59 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.