logo

Analysis & Comparison of X-FILES Stealer Evolution

ID: 4dbb525f-afa4-5ec9-93ac-96f5f27031a2

STIX ID: report--4dbb525f-afa4-5ec9-93ac-96f5f27031a2

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz analyzed multiple variants of the X-FILES infostealer (March 2021–June 2022), documenting evolving features such as expanded system and wallet data collection, directory-crawling for browser data, FTP (FileZilla/WinSCP) theft, base64 string obfuscation, and JSON-based C2 exfiltration. The report outlines phishing and Follina-based delivery chains, provides IoCs (domains, MD5s, filenames), compares variant capabilities, and maps observed behaviors to MITRE ATT&CK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.