A loader built around DLL sideloading is being used to deliver multiple infostealers, and historical YARA hunting suggests the campaign has left a wider trail than a single sample would show.
A newly named loader is being described as unusually evasive, with reports linking it to LegionLoader, CGrabber, and Vidar in a staged delivery chain.