logo

XLoader Executed Through JAR Signing Tool (jarsigner.exe)

ID: 34640f4b-8068-50cf-8e82-55d78557581f

STIX ID: report--34640f4b-8068-50cf-8e82-55d78557581f

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-11-13

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC discovered a distribution campaign of the XLoader infostealer using DLL side-loading: attackers bundle a legitimate, signed jarsigner EXE (renamed Documents2012.exe) with two unsigned malicious DLLs (jli.dll and concrt140e.dll). The tampered jli.dll exports a single malicious entry point that decrypts concrt140e.dll and injects it into aspnet_wp.exe; the decrypted payload executes XLoader to harvest system and browser data and download additional malware. The report includes two MD5 hashes and a delivery URL as indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.