Analysis & Comparison of X-FILES Stealer Evolution
ID: 4dbb525f-afa4-5ec9-93ac-96f5f27031a2
STIX ID: report--4dbb525f-afa4-5ec9-93ac-96f5f27031a2
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz analyzed multiple variants of the X-FILES infostealer (March 2021–June 2022), documenting evolving features such as expanded system and wallet data collection, directory-crawling for browser data, FTP (FileZilla/WinSCP) theft, base64 string obfuscation, and JSON-based C2 exfiltration. The report outlines phishing and Follina-based delivery chains, provides IoCs (domains, MD5s, filenames), compares variant capabilities, and maps observed behaviors to MITRE ATT&CK.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
