Downloaders and droppers are helper programs for various types of Trojans and rootkits. They dont carry any malicious activities by themselves, but just open a way for attack by downloading/decompressing and installing the core malicious modules. OnionDuke (discovered in 2014) is a wrapper over legitimate software by infected Tor nodes. Infections are often consequences of activities like: Clicking malicious links or visiting shady websites or opening attachments sent with spam emails. They often appear in non-persistent form and remove themselves automatically.”]
Source: https://blog.malwarebytes.com/threats/trojan-dropper/