216.73.216.6

Technical Analysis of Xloader Versions 6 and 7

· Published 28/01/2025 08:48 · Modified 28/01/2025 09:07

Export JSON

Essential information

Published
28/01/2025 08:48
Modified
28/01/2025 09:07
Tags
2025-01-28 api resolution encryption formbook information stealer ntdll hook evasion obfuscation process injection xloader
Related entities
200 observables, 1 intrusion sets (apt), 8 techniques (mitre), 2 malware

Description

This analysis examines the latest versions of malware, focusing on its advanced techniques. , successor to , is an targeting browsers, email clients, and FTP applications. The malware employs complex layers to protect critical code and data, complicating analysis efforts. Key features include multi-stage , dynamic string and , and . 's evolution shows increasing sophistication in concealing its operations, with each version introducing new methods to evade detection and hinder reverse engineering.

External references