The Evolution of an Infostealer: Xloader 8.7 Unmasked
ID: f230cb26-4b92-5d4b-b00c-8d671c402c96
STIX ID: report--f230cb26-4b92-5d4b-b00c-8d671c402c96
Feed Name: securityonline.info
ThreatLabz provides a deep-dive analysis of Xloader (formerly Formbook), tracking its evolution to version 8.7 and highlighting advanced code obfuscation, RC4-encrypted C2 communications, decoy C2 addresses, and capabilities such as credential and cookie theft, remote command execution, arbitrary payload execution, and self-removal; the report emphasizes the difficulty of automated and manual analysis and recommends defenders thoroughly study the malware to improve detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
