TF-MAL-apk.xloader
📛 Threat Title
Malware family: XLoader
Description
ThreatFox malware family `apk.xloader`. Printable name: XLoader.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.xloader
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.xloader
IOC database
- Type
- domain
- Value
apk.xloader- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.xloader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.xloader
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
An observed campaign leverage advanced generative-AI techniques to accelerate the reverse-engineering of the loader family commonly known as XLoader . The malware authors continue to deploy obfuscation and encryption tactics multiple packing layers, runtime decryption, sandbox and debugger evasions, and a large set of decoy domains and fake ...
-
web:attack.mitre.org
XLoader is an infostealer malware in use since at least 2016. Previously known and sometimes still referred to as Formbook, XLoader is a Malware as a Service (MaaS) known for stealing data from web browsers, email clients and File Transfer Protocol (FTP) applications.
-
web:blog.checkpoint.com
Check Point Research used generative AI to accelerate XLoader malware analysis - uncovering hidden code, C2 domains, and boosting global protection.
-
web:cybersecuritynews.com
A well-known information-stealing malware called XLoader has received significant upgrades in its latest versions, making it considerably harder to detect and analyze than before. Originally derived from a malware family known as FormBook, which first surfaced in 2016, XLoader was rebranded and relaunched in early 2020, and since then, its developers have consistently pushed new updates to ...
-
web:gurucul.com
"Technical Analysis of Xloader Versions 6 and 7 | Part 2" examines the advanced obfuscation techniques used by Xloader versions 6 and 7 to conceal critical code and data. The malware continues to employ hardcoded decoy lists to blend malicious C2 traffic with legitimate website traffic. These decoy lists and the actual C2 server are […]
-
web:malware.news
IntroductionXloader is a malware family that is the successor to Formbook with information stealing capabilities targeting web browsers, email clients, and File Transfer Protocol (FTP) applications. The malware is also able to deploy second-stage payloads to an infected system. The author of Xloader regularly adds new functionality to target more applications and features to increase the ...
-
web:securityboulevard.com
IntroductionXloader is a malware family that is the successor to Formbook with information stealing capabilities targeting web browsers, email clients, and File Transfer Protocol (FTP) applications. The malware is also able to deploy second-stage payloads to an infected system. The author of Xloader ...
-
web:thehackernews.com
XLoader malware is spreading via Eclipse Jarsigner using DLL side-loading, evading detection with encrypted decoys and advanced obfuscation.
-
web:www.antiy.net
To increase the difficulty of extracting the key and encrypted code block, XLoader dynamically calculates the start and end feature values and keys of the encrypted code block at runtime to prevent automated extraction. Figure 3 ‑6 XLoader decrypted code block To prevent memory dump, XLoader will re-encrypt the code after the function is used.
-
web:www.zscaler.com
Key Takeaways Formbook, introduced in 2016, was rebranded as Xloader in early 2020. After that, Xloader adopted a Malware -as-a-Service (MaaS) model, renting command-and-control (C2) infrastructure to cybercriminals. Xloader is a malware family that steals data from a variety of targeted applications such as web browsers, email clients, and File Transfer Protocol (FTP) applications. Xloader can ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.