logo

Xloader Returns with New Infection Technique

ID: 072816bb-6106-5add-93d6-2cb7702f540a

STIX ID: report--072816bb-6106-5add-93d6-2cb7702f540a

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This technical analysis details a multi-stage Xloader infostealer delivery: a malicious PDF drops an embedded XLSX which fetches an RTF that abuses CVE-2017-11882 to launch an obfuscated .NET loader (vbc.exe); that loader decodes and loads staged assemblies, uses steganography (a compressed bitmap in resources) to extract a second-stage .NET payload (MajorRevision.exe), and ultimately performs process hollowing to inject a MASM-compiled Xloader binary which persists via a registry Run key and exfiltrates credentials, keystrokes, clipboard data, cookies, and screenshots; the report includes MITRE ATT&CK technique mappings, detailed IOCs (file hashes and C2 URLs), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.