home.social

#xloader — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #xloader, aggregated by home.social.

fetched live
  1. #xloader 's (c6713b3c5ba4da5044d96463cae74227a6a898abb051a5f75ab7b508eb20f7e1) choice of which executable to inject into continues to fascinate me...

  2. #xloader 's (c6713b3c5ba4da5044d96463cae74227a6a898abb051a5f75ab7b508eb20f7e1) choice of which executable to inject into continues to fascinate me...

  3. Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service

    Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.

    Pulse ID: 6a5dec09c0c4b7d2a00d7b2c
    Pulse Link: otx.alienvault.com/pulse/6a5de
    Pulse Author: AlienVault
    Created: 2026-07-20 09:36:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #CyberSecurity #EDR #Email #FormBook #Government #Healthcare #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #Remcos #RemoteAccessTrojan #Tesla #Trojan #Worm #XLoader #XWorm #bot #AlienVault

  4. Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service

    Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.

    Pulse ID: 6a5dec09c0c4b7d2a00d7b2c
    Pulse Link: otx.alienvault.com/pulse/6a5de
    Pulse Author: AlienVault
    Created: 2026-07-20 09:36:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #CyberSecurity #EDR #Email #FormBook #Government #Healthcare #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #Remcos #RemoteAccessTrojan #Tesla #Trojan #Worm #XLoader #XWorm #bot #AlienVault

  5. 2026-04-13 (Monday): #XLoader (#Formbook) infection.

    A #pcap of the traffic, the associated email and #malware samples are available at malware-traffic-analysis.net/2

  6. 2026-04-13 (Monday): #XLoader (#Formbook) infection.

    A #pcap of the traffic, the associated email and #malware samples are available at malware-traffic-analysis.net/2

  7. Also at https://cstaipas\.pt/encrypt, though this one is #xloader, a fake c2 at: http://www.emberfmeadowzu\.store/jmy3/

  8. #CheckPoint Research demonstrated a new way to use #ChatGPT for #malware analysis directly from the web interface, analyzing #XLoader malware. The workflow using exported IDA data enables static analysis, rapid decryption, IoC extraction, and hidden C2 discovery.

    research.checkpoint.com/2025/g

  9. #malware #opendir #xloader (small one works, big one not so much) at:

    https://royfils\.com/encrypt/

    2cd9b8fb88e7cbbc5c049441fb61e0aea7be23dc7aa2c109c13abefe7a2ac943

    4733feaca04e871d4e0bb052f2437a2f46f10852602ea4f8b2f0170f4838dd87

  10. 🤺 AI vs. XLoader: Guess who’s winning?

    #CheckPoint Research used generative AI to tear through #XLoader, one of the most encrypted, evasive malware strains — uncovering its secrets in mere hours.

    And here’s the twist: It all happened with #ChatGPT. No heavy tooling. No waiting.

    #AI is changing the rules of malware analysis, and the race just shifted in our favor: blog.checkpoint.com/research/c

    #CyberSecurity #AIsecurity

  11. Social media post I wrote for my employer on other platforms: 2025-02-26 (Wednesday): #XLoader (#Formbook) distributed through #malspam.

    The email has an attached PDF document. The PDF has links for a ZIP download, and the ZIP contains files using DLL side-loading for XLoader.

    Details at github.com/PaloAltoNetworks/Un

  12. Social media post I wrote for my employer on other platforms: 2025-02-26 (Wednesday): #XLoader (#Formbook) distributed through #malspam.

    The email has an attached PDF document. The PDF has links for a ZIP download, and the ZIP contains files using DLL side-loading for XLoader.

    Details at github.com/PaloAltoNetworks/Un

  13. 2025-01-30 (Thursday): #XLoader infection

    Unlike my previous XLoader infections, this one didn't run in a VM, so I used a physical host.

    A #pcap of the infection traffic, the associated malware samples, and more info is available at malware-traffic-analysis.net/2

  14. 2025-01-30 (Thursday): #XLoader infection

    Unlike my previous XLoader infections, this one didn't run in a VM, so I used a physical host.

    A #pcap of the infection traffic, the associated malware samples, and more info is available at malware-traffic-analysis.net/2

  15. Hey @da_667 ...you seen this UA with #xloader yet?

    <url method="POST" uri="/k2i2/" host="www\.gayhxi\.info" user_agent="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/538.1 (KHTML, like Gecko) FoxyWhore Safari/538.1"/>

  16. #xloader continues to change...never seen a samsung UA before:

    fbe048c713eda8c6d74504c440ecba4507760aed537fbba6171a4566b6452455

  17. This report has a link to a real example of how Revolver Rabbit uses an RDGA in Xloader. Tracking their domains is tricky and I suspect the full size is much larger than we have caught. if they invest such huge sums into their infrastructure, they must be making bank. #dns #threatintel #threatintelligence #malware #xloader #infoblox #rdga #cybercrime #cybersecurity #infosec #phishing @InfobloxThreatIntel bleepingcomputer.com/news/secu

  18. This report has a link to a real example of how Revolver Rabbit uses an RDGA in Xloader. Tracking their domains is tricky and I suspect the full size is much larger than we have caught. if they invest such huge sums into their infrastructure, they must be making bank. #dns #threatintel #threatintelligence #malware #xloader #infoblox #rdga #cybercrime #cybersecurity #infosec #phishing @InfobloxThreatIntel bleepingcomputer.com/news/secu

  19. We just released a landscape review of Registered DGAs. We review the many ways threat actors are leveraging these algorithms -- including malware, phishing, scams, porns, you name it. Our RDGA detectors find tens of thousands of domains every day, and we've seen the use continue to rise over the last several years. Most folks aren't even aware since actors are doing this in DNS and it often isn't obvious. #dns #threatintel #cybersecurity #cybercrime #infoblox #RDGA #DGA #DDGA #malware #phishing #scams #infoblox #infobloxthreatintel #cybersecurity #threatactor #c2 #revolverrabbit #threatintelligence #cyber #cyberintelligence #xloader #formbook #abusedtld insights.infoblox.com/resource

  20. We just released a landscape review of Registered DGAs. We review the many ways threat actors are leveraging these algorithms -- including malware, phishing, scams, porns, you name it. Our RDGA detectors find tens of thousands of domains every day, and we've seen the use continue to rise over the last several years. Most folks aren't even aware since actors are doing this in DNS and it often isn't obvious. #dns #threatintel #cybersecurity #cybercrime #infoblox #RDGA #DGA #DDGA #malware #phishing #scams #infoblox #infobloxthreatintel #cybersecurity #threatactor #c2 #revolverrabbit #threatintelligence #cyber #cyberintelligence #xloader #formbook #abusedtld insights.infoblox.com/resource

  21. The malware pays homage to the League of Legends character Jinx, prominently featuring the character on its advertising poster and command-and-control login panel. JinxLoader’s primary purpose is straightforward – loading malware.

    #Cybersecurity #Formbook #JinxLoader #Malware #Xloader

    cybersec84.wordpress.com/2024/

  22. The malware pays homage to the League of Legends character Jinx, prominently featuring the character on its advertising poster and command-and-control login panel. JinxLoader’s primary purpose is straightforward – loading malware.

    #Cybersecurity #Formbook #JinxLoader #Malware #Xloader

    cybersec84.wordpress.com/2024/

  23. #XLoader #malware has targeted #macOS since 2015, but it was recently updated. It now pretends to be an #Office application, so it can infect users’ machines and steal information from their clipboards and browsers. tchlp.com/3PclOIr

  24. #XLoader #malware has targeted #macOS since 2015, but it was recently updated. It now pretends to be an #Office application, so it can infect users’ machines and steal information from their clipboards and browsers. tchlp.com/3PclOIr

  25. #Researchers have discovered a new #variant of the #XLoader #malware that is better at dodging #Apple’s #security measures as it tries to steal sensitive information from #macOS devices. tchlp.com/47GTe9v

  26. #Researchers have discovered a new #variant of the #XLoader #malware that is better at dodging #Apple’s #security measures as it tries to steal sensitive information from #macOS devices. tchlp.com/47GTe9v

  27. XLoader, ein Nachfolger des älteren Windows-Trojaners Formbook, greift nun auch Daten unter macOS ab.
    XLoader: Windows-Schadsoftware kann jetzt auch macOS treffen