logo

Latest Xloader Obfuscation Code & C2 Protocol

ID: 783405fc-0955-5496-8370-7e55099679d8

STIX ID: report--783405fc-0955-5496-8370-7e55099679d8

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-05-01

...
...

This technical analysis of Xloader (FormBook rebrand) details enhancements since version 8.1: more sophisticated code obfuscation (encrypted strings, runtime-decrypted functions, opaque predicates), changes to function/egg construction, and an obfuscated custom decryption routine; it also documents Xloader’s network protocol and multi-layer RC4/Base64 encryption, its use of 65 decrypted C2 IPs (randomly probed to hide real servers), HTTP GET/POST behaviors for PKT2 and exfiltration, and the malware’s command set (file execution, update, self-removal, credential theft, payload download/execute, reboot/shutdown).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.