logo

XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers

ID: 9a0b4596-2952-5edc-a9e8-4868cffe70fe

STIX ID: report--9a0b4596-2952-5edc-a9e8-4868cffe70fe

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

XLoader (formerly FormBook) is an actively developed information-stealing malware that exfiltrates browser and email credentials, executes arbitrary commands, and can deploy additional payloads. Recent versions (from 8.1 onward) add strong code/network obfuscation—including a runtime-decrypted pool of 65 C2 IPs (randomly contacting 16), RC4 and SHA-1 based layering, and Base64-encoded parameters—making static analysis and automated detection difficult; distribution remains primarily via phishing and malicious attachments, and detection is tracked as Win32.PWS.XLoader.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.