#XLoader
2025-01-30 (Thursday): #XLoader infection. Unlike my previous XLoader infections, this one didn't run in my VM, so I used a physical host. A #pcap of the infection traffic, the associated malware samples, and more info is available at malware-traffic-analysis.net/2025/01/30/i...
January 30, 2025 at 6:32 PM
2024-11-22 (Friday) #XLoader / #Formbook: I've been fired by my non-existent HR department. At least I got a "salary-receipt.exe" bazaar.abuse.ch/sample/003b5...

Tria.ge and Any.Run don't identify the malware, but Joe Sandbox does: www.joesandbox.com/analysis/156...

Also runs in my lab just fine
November 22, 2024 at 7:42 PM
Cybercriminals use a legitimate Jarsigner within a ZIP archive to deploy XLoader malware. A modified DLL in the archive decrypts and injects XLoader (concrt140e.dll) into aspnet_wp.exe via DLL side-loading, bypassing security. XLoader steals data and downloads more malware.#ZipArchiveMalware
February 20, 2025 at 12:05 PM
~Checkpoint~
Generative AI drastically reduces reverse engineering time for the complex XLoader malware from days to hours.
-
IOCs: taxi-in[. ]online, taskcomputer[. ]xyz, synergydrop[. ]xyz
-
#AI #Malware #ThreatIntel #XLoader
AI Accelerates XLoader Malware Analysis
research.checkpoint.com
November 3, 2025 at 5:01 PM
Social media post I wrote for my employer on other platforms: 2025-02-26 (Wednesday): #XLoader (#Formbook) sent thru #malspam. Email has an attached PDF document. PDF has links for a ZIP download, and the ZIP contains files using DLL side-loading for XLoader. Details at github.com/PaloAltoNetw...
February 27, 2025 at 2:44 PM
2026-04-13 (Monday): #XLoader ( #Formbook ) infection. A #pcap of the traffic, along with the associated email and malware samples are available at malware-traffic-analysis.net/2026/index.h...
April 14, 2026 at 9:47 PM
MacOS malware keeps improving as Apple products become a more important target for cybercriminal groups.
MacOS version of info-stealing XLoader gets an upgrade
A previous macOS-oriented version of XLoader had some limitations. Researchers say the info-stealer now can run on more machines while potentially dodging detection.
therecord.media
August 23, 2023 at 9:41 AM
From XLoader to Phantom Stealer: A DHL-Themed multi-stage Infection Chain
From XLoader to Phantom Stealer: A DHL-Themed multi-stage Infection Chain
medium.com
January 28, 2026 at 8:54 PM
Xloader deep dive: Link-based malware delivery via SharePoint impersonation
Xloader deep dive: Link-based malware delivery via SharePoint impersonation
An in-depth analysis of Xloader malware delivered via spoofed SharePoint notifications.
buff.ly
December 13, 2024 at 6:36 AM
¿Tu Android está seguro? El malware XLoader volvió más peligroso que nunca: Ahora se disfraza de Chrome
Se activa automáticamente y opera en segundo plano, eludiendo su detección.
www.fayerwayer.com/moviles/2024...
February 19, 2024 at 5:15 PM
2025-02-26 (Wednesday): #XLoader (#Formbook) distributed through #malspam. The email has an attached PDF document. The PDF has links for a ZIP download, and the ZIP contains files that use DLL side-loading for XLoader.

bit.ly/4bgKRU8
Unit42-timely-threat-intel/2025-02-26-IOCs-for-XLoader-infection.txt at main · PaloAltoNetworks/Unit42-timely-threat-intel
A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence. - PaloAltoNetworks/Unit42-timely-threat-intel
bit.ly
February 28, 2025 at 2:06 AM
XLoader Malware Uses PowerShell and Process Hollowing socprime.com/active-threa...
XLoader Malware Uses PowerShell and Process Hollowing
XLoader uses JScript, PowerShell, ConfuserEx2, and process hollowing to inject its payload and steal data from compromised Windows systems
socprime.com
September 8, 2026 at 11:08 AM
November 4, 2025 at 12:35 PM
-SEC replaces cryptocurrency fraud unit
-New CISA layoffs
-Sanctioned crypto entities thrived last year
-New Pegasus infections spotted
-New JS obfuscation technique spotted in the wild
-Ghost ransomware still active
-Malware reports on Darcula, Snake keylogger, Xloader, SPAWNCHIMERA
February 21, 2025 at 9:09 AM
Beware Of Malicious SharePoint Notifications That Delivers Xloader Malware gbhackers.com/sharepoint-x...
Beware Of Malicious SharePoint Notifications That Delivers Xloader Malware
Through the use of XLoader and impersonating SharePoint notifications, researchers were able to identify a sophisticated malware delivery
gbhackers.com
December 22, 2024 at 10:56 AM
Android XLoader malware can now auto-execute after installation
Android XLoader malware can now auto-execute after installation
A new version of the XLoader Android malware was discovered that automatically executes on devices it infects, requiring no user interaction to launch.
www.bleepingcomputer.com
February 8, 2024 at 6:41 PM
Zscaler ThreatLabz researchers present the second part of a technical analysis of Xloader versions 6 & 7, covering how Xloader obfuscates the command-and-control (C2), and the network communication protocol. www.zscaler.com/blogs/securi...
February 17, 2025 at 10:26 AM
📢 Xloader v8.1+ : nouvelles techniques d'obfuscation et protocole C2 détaillés
📝 ## 🔍 Contexte

Publié le 31 mars 2026 par ThreatLabz (Zscaler), cet article c…
https://cyberveille.ch/posts/2026-04-05-xloader-v8-1-nouvelles-techniques-d-obfuscation-et-protocole-c2-detailles/ #C2_protocol #Cyberveille
April 4, 2026 at 11:30 PM
Beware: JinxLoader, a new Go-based #malware loader, is proliferating via phishing attacks, providing access to Formbook and XLoader.
thehackernews.com/2024/01/new-...
#cyberattack #cybersecurity #hacking
New JinxLoader Targeting Users with Formbook and XLoader Malware
A new malware loader called JinxLoader is being used by threat actors to deliver payloads such as Formbook and XLoader.
thehackernews.com
January 1, 2024 at 9:24 PM
How do you actually use AI with Suricata in practice?

In this webinar, Peter Manev walks through analyzing network metadata and alert payloads with AI as part of the workflow, using XLoader as the example.

Replay: www.youtube.com/watch?v=tuR2...

#Suricata #OpenSource #Webinar
Webinar: AI Analysis of Suricata Network Metadata and Alert Payloads with Peter Manev
YouTube video by OISF-Suricata
www.youtube.com
May 28, 2026 at 1:46 PM
2025-08-11 (Monday): Quick post of an #XLoader ( #Formbook ) infection, with a #pcap, email, and #malware sample available at www.malware-traffic-analysis.net/2025/08/11/i...
August 12, 2025 at 2:32 PM