logo

Technical Analysis of Zloader Updates

ID: ffcb32e2-f3ca-5473-bf40-d42d72689b34

STIX ID: report--ffcb32e2-f3ca-5473-bf40-d42d72689b34

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-09-22

Date Updated: 2026-05-01

...
...

This report provides a technical analysis of recent Zloader updates: the malware now accepts generic filenames (Updater.exe/Updater.dll), adds XOR-based obfuscation and integrity-level checks to evade sandboxes, changes its static configuration format (including a mini JSON for DNS resolvers), replaces TLS in its DNS tunneling with Base32 plus a custom XOR-based decode using a session key, adds WebSocket support to blend with legitimate traffic, and introduces LDAP functions in its interactive shell to improve network discovery and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.