Xloader Returns with New Infection Technique
ID: 072816bb-6106-5add-93d6-2cb7702f540a
STIX ID: report--072816bb-6106-5add-93d6-2cb7702f540a
Feed Name: Cyble Blog
This technical analysis details a multi-stage Xloader infostealer delivery: a malicious PDF drops an embedded XLSX which fetches an RTF that abuses CVE-2017-11882 to launch an obfuscated .NET loader (vbc.exe); that loader decodes and loads staged assemblies, uses steganography (a compressed bitmap in resources) to extract a second-stage .NET payload (MajorRevision.exe), and ultimately performs process hollowing to inject a MASM-compiled Xloader binary which persists via a registry Run key and exfiltrates credentials, keystrokes, clipboard data, cookies, and screenshots; the report includes MITRE ATT&CK technique mappings, detailed IOCs (file hashes and C2 URLs), and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
