logo

X-VPN Installer Hijacked to Spread STX RAT Malware

ID: cd15a4ea-9fe3-5ec6-859a-98dd4cb59000

STIX ID: report--cd15a4ea-9fe3-5ec6-859a-98dd4cb59000

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Do Son

...
...

A month-long supply-chain operation trojanized installers for cryptocurrency trading tools and ultimately an X-VPN package used by millions; a malicious CRYPTBASE.dll sideloaded STX RAT into memory to steal credentials and provide remote access. The campaign was hosted via a Bitbucket repo and used infrastructure tied to supp0v3.com, and X-VPN released a patch (version 77.5.3) to mitigate the DLL sideloading (CWE-427) vulnerability—users who installed from unofficial sources are at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.