ATT&CKReferencesANY.RUN XLoader 2023

ANY.RUN XLoader 2023

ANY.RUN. (2023, February 28). XLoader/FormBook: Encryption Analysis and Malware Decryption . Retrieved March 11, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareXLoader

XLoader features encrypted functions using the RC4 algorithm and bytecode operations.

T1055.012
Process Hollowing
MalwareXLoader

XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory.

T1497
Virtualization/Sandbox Evasion
MalwareXLoader

XLoader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.