logo

Technical Analysis of Xloader Versions 6 and 7 P1

ID: a4ab3abd-0a93-5e5e-abb0-0f33c33f1fa1

STIX ID: report--a4ab3abd-0a93-5e5e-abb0-0f33c33f1fa1

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Technical analysis of Xloader (versions 6 and 7) detailing persistence via copies to %APPDATA% or %PROGRAMFILES% and Run/Policies registry entries, process hollowing and APC-based injection into explorer.exe and SysWOW64 executables, and sophisticated multi-layer RC4+subtraction encryption for code, strings, and API hashes. The report documents dynamic key construction, egg-hunting decryption routines, code encryption around critical API calls, NTDLL copy-based hook evasion, example target executable names, and evolution of obfuscation techniques with pseudocode to aid detection and analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.