logo

XE Group: From Credit Card Skimming to Exploiting Zero-Days

ID: dafa39a2-40c3-5b64-bb85-a083e2b206dd

STIX ID: report--dafa39a2-40c3-5b64-bb85-a083e2b206dd

Feed Name: Intezer Blog

Threat Score
82/100

Date Published: 2025-02-03

Date Updated: 2026-04-28

Author: Nicole Fishbein

...
...

This report analyzes XE Group — a long-active cybercriminal actor that has shifted from credit-card skimming to targeted information theft — detailing exploitation of two VeraCore vulnerabilities (CVE-2024-57968, CVE-2025-25181), the deployment and evolution of ASPX webshells, post-exploitation activity (including a PowerShell reflective loader and Meterpreter C2), persistence across multiple years, operational TTPs, IOCs (file hashes, IP addresses, YARA rules), and a vendor disclosure timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.