#xloader — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #xloader, aggregated by home.social.
-
#xloader 's (c6713b3c5ba4da5044d96463cae74227a6a898abb051a5f75ab7b508eb20f7e1) choice of which executable to inject into continues to fascinate me...
-
#xloader 's (c6713b3c5ba4da5044d96463cae74227a6a898abb051a5f75ab7b508eb20f7e1) choice of which executable to inject into continues to fascinate me...
-
Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.
Pulse ID: 6a5dec09c0c4b7d2a00d7b2c
Pulse Link: https://otx.alienvault.com/pulse/6a5dec09c0c4b7d2a00d7b2c
Pulse Author: AlienVault
Created: 2026-07-20 09:36:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #CyberSecurity #EDR #Email #FormBook #Government #Healthcare #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #Remcos #RemoteAccessTrojan #Tesla #Trojan #Worm #XLoader #XWorm #bot #AlienVault
-
Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.
Pulse ID: 6a5dec09c0c4b7d2a00d7b2c
Pulse Link: https://otx.alienvault.com/pulse/6a5dec09c0c4b7d2a00d7b2c
Pulse Author: AlienVault
Created: 2026-07-20 09:36:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #CyberSecurity #EDR #Email #FormBook #Government #Healthcare #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #Remcos #RemoteAccessTrojan #Tesla #Trojan #Worm #XLoader #XWorm #bot #AlienVault
-
Couple #reverseloader -> #xloader #opendir at:
http://107.175.246 .42/25/
http://89.40.31 .143/img/ -
2026-04-13 (Monday): #XLoader (#Formbook) infection.
A #pcap of the traffic, the associated email and #malware samples are available at https://malware-traffic-analysis.net/2026/04/13/index.html
-
2026-04-13 (Monday): #XLoader (#Formbook) infection.
A #pcap of the traffic, the associated email and #malware samples are available at https://malware-traffic-analysis.net/2026/04/13/index.html
-
Also at https://cstaipas\.pt/encrypt, though this one is #xloader, a fake c2 at: http://www.emberfmeadowzu\.store/jmy3/
-
#CheckPoint Research demonstrated a new way to use #ChatGPT for #malware analysis directly from the web interface, analyzing #XLoader malware. The workflow using exported IDA data enables static analysis, rapid decryption, IoC extraction, and hidden C2 discovery.
https://research.checkpoint.com/2025/generative-ai-for-reverse-engineering/
-
🤺 AI vs. XLoader: Guess who’s winning?
#CheckPoint Research used generative AI to tear through #XLoader, one of the most encrypted, evasive malware strains — uncovering its secrets in mere hours.
And here’s the twist: It all happened with #ChatGPT. No heavy tooling. No waiting.
#AI is changing the rules of malware analysis, and the race just shifted in our favor: https://blog.checkpoint.com/research/cracking-xloader-with-ai-how-generative-models-accelerate-malware-analysis
-
-
First time I've seen #xloader use @tumblr for traffic noise:
-
2025-01-30 (Thursday): #XLoader infection
Unlike my previous XLoader infections, this one didn't run in a VM, so I used a physical host.
A #pcap of the infection traffic, the associated malware samples, and more info is available at https://malware-traffic-analysis.net/2025/01/30/index.html
-
2025-01-30 (Thursday): #XLoader infection
Unlike my previous XLoader infections, this one didn't run in a VM, so I used a physical host.
A #pcap of the infection traffic, the associated malware samples, and more info is available at https://malware-traffic-analysis.net/2025/01/30/index.html
-
Technical Analysis of Xloader Versions 6 and 7 | Part 1
#Xloader
https://www.zscaler.com/blogs/security-research/technical-analysis-xloader-versions-6-and-7-part-1 -
An #expiro (believe it or not) dropping #xloader
https://app.any.run/tasks/43f807db-2361-4807-8e05-19831c56b5e4
fake c2 and campaign:
http ://www.sunnyz.store/px6j -
-
#xloader continues to change...never seen a samsung UA before:
fbe048c713eda8c6d74504c440ecba4507760aed537fbba6171a4566b6452455
-
This report has a link to a real example of how Revolver Rabbit uses an RDGA in Xloader. Tracking their domains is tricky and I suspect the full size is much larger than we have caught. if they invest such huge sums into their infrastructure, they must be making bank. #dns #threatintel #threatintelligence #malware #xloader #infoblox #rdga #cybercrime #cybersecurity #infosec #phishing @InfobloxThreatIntel https://www.bleepingcomputer.com/news/security/revolver-rabbit-gang-registers-500-000-domains-for-malware-campaigns/
-
This report has a link to a real example of how Revolver Rabbit uses an RDGA in Xloader. Tracking their domains is tricky and I suspect the full size is much larger than we have caught. if they invest such huge sums into their infrastructure, they must be making bank. #dns #threatintel #threatintelligence #malware #xloader #infoblox #rdga #cybercrime #cybersecurity #infosec #phishing @InfobloxThreatIntel https://www.bleepingcomputer.com/news/security/revolver-rabbit-gang-registers-500-000-domains-for-malware-campaigns/
-
We just released a landscape review of Registered DGAs. We review the many ways threat actors are leveraging these algorithms -- including malware, phishing, scams, porns, you name it. Our RDGA detectors find tens of thousands of domains every day, and we've seen the use continue to rise over the last several years. Most folks aren't even aware since actors are doing this in DNS and it often isn't obvious. #dns #threatintel #cybersecurity #cybercrime #infoblox #RDGA #DGA #DDGA #malware #phishing #scams #infoblox #infobloxthreatintel #cybersecurity #threatactor #c2 #revolverrabbit #threatintelligence #cyber #cyberintelligence #xloader #formbook #abusedtld https://insights.infoblox.com/resources-research-report/infoblox-research-report-registered-dgas-the-prolific-new-menace-no-one-is-talking-about
-
We just released a landscape review of Registered DGAs. We review the many ways threat actors are leveraging these algorithms -- including malware, phishing, scams, porns, you name it. Our RDGA detectors find tens of thousands of domains every day, and we've seen the use continue to rise over the last several years. Most folks aren't even aware since actors are doing this in DNS and it often isn't obvious. #dns #threatintel #cybersecurity #cybercrime #infoblox #RDGA #DGA #DDGA #malware #phishing #scams #infoblox #infobloxthreatintel #cybersecurity #threatactor #c2 #revolverrabbit #threatintelligence #cyber #cyberintelligence #xloader #formbook #abusedtld https://insights.infoblox.com/resources-research-report/infoblox-research-report-registered-dgas-the-prolific-new-menace-no-one-is-talking-about
-
Not sure when it happened, but #xloader / #formbook now appears to rotate through campaign ID's:
https://app.any.run/tasks/4cb7b5ef-5c1d-4565-a370-5d0cf1a5c255
-
Not sure when it happened, but #xloader / #formbook now appears to rotate through campaign ID's:
https://app.any.run/tasks/4cb7b5ef-5c1d-4565-a370-5d0cf1a5c255
-
The malware pays homage to the League of Legends character Jinx, prominently featuring the character on its advertising poster and command-and-control login panel. JinxLoader’s primary purpose is straightforward – loading malware.
-
The malware pays homage to the League of Legends character Jinx, prominently featuring the character on its advertising poster and command-and-control login panel. JinxLoader’s primary purpose is straightforward – loading malware.
-
#XLoader #malware has targeted #macOS since 2015, but it was recently updated. It now pretends to be an #Office application, so it can infect users’ machines and steal information from their clipboards and browsers. https://tchlp.com/3PclOIr
-
#XLoader #malware has targeted #macOS since 2015, but it was recently updated. It now pretends to be an #Office application, so it can infect users’ machines and steal information from their clipboards and browsers. https://tchlp.com/3PclOIr
-
#Researchers have discovered a new #variant of the #XLoader #malware that is better at dodging #Apple’s #security measures as it tries to steal sensitive information from #macOS devices. https://tchlp.com/47GTe9v
-
#Researchers have discovered a new #variant of the #XLoader #malware that is better at dodging #Apple’s #security measures as it tries to steal sensitive information from #macOS devices. https://tchlp.com/47GTe9v
-
The most recent iteration of XLoader has successfully addressed this restriction by utilizing programming languages such as Objective C and C.
-
The most recent iteration of XLoader has successfully addressed this restriction by utilizing programming languages such as Objective C and C.
-
📬 XLoader: macOS-Malware tarnt sich als OfficeNote-Anwendung
#ITSicherheit #Malware #DineshDevadoss #Formbook #Keylogger #macOS #macOSMalware #OfficeNote #PhilStokes #SentinelOne #XLoader https://tarnkappe.info/artikel/it-sicherheit/xloader-macos-malware-tarnt-sich-als-officenote-anwendung-279902.html -
📬 XLoader: macOS-Malware tarnt sich als OfficeNote-Anwendung
#ITSicherheit #Malware #DineshDevadoss #Formbook #Keylogger #macOS #macOSMalware #OfficeNote #PhilStokes #SentinelOne #XLoader https://tarnkappe.info/artikel/it-sicherheit/xloader-macos-malware-tarnt-sich-als-officenote-anwendung-279902.html -
XLoader, ein Nachfolger des älteren Windows-Trojaners Formbook, greift nun auch Daten unter macOS ab.
XLoader: Windows-Schadsoftware kann jetzt auch macOS treffen