logo

Technical Analysis of Xloader Versions 6 and 7 P2

ID: 232b7f46-ca1a-5f5b-be0e-aa2f6916bca4

STIX ID: report--232b7f46-ca1a-5f5b-be0e-aa2f6916bca4

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-09-25

Date Updated: 2026-05-01

...
...

### Executive summary This technical analysis describes Xloader's multi-layered C2 decryption scheme, detailing how the malware constructs dynamic 20-byte keys, decrypts decoy and real C2 entries (using Base64, RC4 and subtraction algorithms), appends or extracts URL paths per version, and uses decoy domains to disguise real command-and-control communications — information that supports detection and reverse-engineering of the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.