XLoader malware Sharpens Obfuscation, Masks C2 Traffic via Decoy Servers
ID: 631b46f6-345b-5ed1-ae19-dbe480be75bd
STIX ID: report--631b46f6-345b-5ed1-ae19-dbe480be75bd
Feed Name: GBHackers
Threat Score
XLoader (formerly Formbook) is an actively developed information‑stealing trojan whose recent 8.x builds add layered obfuscation, custom RC4-based decryption, and multi-key/encrypted C2 communications with many decoy endpoints; it supports credential theft, keystroke logging, remote execution and payload delivery, and the report includes SHA256 IOCs and recommended detection/hardening actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
