ATT&CKReferencesGoogle XLoader 2017

Google XLoader 2017

Nart Villeneuve, Randi Eitzman, Sandor Nemes & Tyler Dean, Google Cloud. (2017, October 5). Significant FormBook Distribution Campaigns Impacting the U.S. and South Korea. Retrieved March 11, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1055.012
Process Hollowing
MalwareXLoader

XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory.

T1056.001
Keylogging
MalwareXLoader

XLoader can capture keystrokes from the victim machine.

T1059.010
AutoHotKey & AutoIT
MalwareXLoader

XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine.

T1071.001
Web Protocols
MalwareXLoader

XLoader uses HTTP and HTTPS for command and control communication.

T1113
Screen Capture
MalwareXLoader

XLoader can capture screenshots on compromised hosts.

T1115
Clipboard Data
MalwareXLoader

XLoader can collect data stored in the victim's clipboard.

T1140
Deobfuscate/Decode Files or Information
MalwareXLoader

XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader.

T1185
Browser Session Hijacking
MalwareXLoader

XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions.

T1497.001
System Checks
MalwareXLoader

XLoader performs timing checks using the Read-Time Stamp Counter (RDTSC) instruction on the victim CPU.

T1529
System Shutdown/Reboot
MalwareXLoader

XLoader can initiate a system reboot or shutdown.

T1539
Steal Web Session Cookie
MalwareXLoader

XLoader can capture web session cookies and session information from victim browsers.

T1547.001
Registry Run Keys / Startup Folder
MalwareXLoader

XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start.

T1555
Credentials from Password Stores
MalwareXLoader

XLoader can collect credentials stored in email clients.

T1555.003
Credentials from Web Browsers
MalwareXLoader

XLoader can gather credentials from several web browsers.

T1566.001
Spearphishing Attachment
MalwareXLoader

XLoader has been delivered as a phishing attachment, including PDFs with embedded links, Word and Excel files, and various archive files (ZIP, RAR, ACE, and ISOs) containing EXE payloads.

T1622
Debugger Evasion
MalwareXLoader

XLoader uses anti-debugging mechanisms such as calling `NtQueryInformationProcess` with `InfoClass=7`, referencing `ProcessDebugPort`, to determine if it is being analyzed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.