logo

Backdoor Xtrat Continues To Evade Detection

ID: 6c1b712a-81ac-5c95-9149-869cb163c1a0

STIX ID: report--6c1b712a-81ac-5c95-9149-869cb163c1a0

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** Zscaler observed a live example of the Backdoor Xtrat malware distributed from a malicious PHP URL that delivered a ZIP containing an EXE; the report includes file MD5s, VirusTotal detection counts, dropped filenames, network indicators (C2 domains, an IP and ports), observed behaviors (process injection, dropped PE files, remote command/data exfiltration), and suggested Snort signatures — noting the malware is older but remains active with many changing C2 domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.