logo

From credit card fraud to zero-day exploits: Xe Group expanding cybercriminal efforts

ID: bd78918a-99af-5246-aea4-92a3ded94f02

STIX ID: report--bd78918a-99af-5246-aea4-92a3ded94f02

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2025-02-03

Date Updated: 2026-04-21

Author: Greg Otto

...
...

XE Group, a decade-old cybercriminal organization, has shifted from e-commerce card-skimming to exploiting zero-day flaws in supply-chain software (VeraCore), leveraging upload validation and SQL injection flaws to implant webshells, exfiltrate data, and maintain multi-year persistence; researchers observed active exploitation in 2024, reuse of credentials from a 2020 breach, C2 infrastructure and automated data exfiltration tools, and at least one unpatched SQL flaw that elevates supply chain risk for manufacturers and distributors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.