logo

Latest Xloader Obfuscation Methods and Network Protocol

ID: 9e41ab6a-612c-546f-93b3-fc25918e0754

STIX ID: report--9e41ab6a-612c-546f-93b3-fc25918e0754

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: ThreatLabz (Zscaler)

...
...

Xloader (formerly FormBook) is an actively maintained information‑stealer; this Zscaler ThreatLabz analysis examines versions 8.1–8.7 and documents enhanced code obfuscation (dynamic function decryption, opaque predicates, obfuscated constants), multi-layered network encryption using RC4 and SHA-1 derived keys, use of decoy C2 IPs, and a set of network commands for credential exfiltration, payload download/execution, updates, and removal; the report also supplies sample IOCs (SHA256 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.