ATT&CKReferencesZscaler XLoader 2025

Zscaler XLoader 2025

Zscaler Threatlabz. (2025, January 27). Technical Analysis of Xloader Versions 6 and 7 | Part 1. Retrieved March 11, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareXLoader

XLoader features encrypted functions using the RC4 algorithm and bytecode operations.

T1055.004
Asynchronous Procedure Call
MalwareXLoader

XLoader injects code into the APC queue using `NtQueueApcThread` API.

T1055.012
Process Hollowing
MalwareXLoader

XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory.

T1106
Native API
MalwareXLoader

XLoader uses the native Windows API for functionality, including defense evasion.

T1140
Deobfuscate/Decode Files or Information
MalwareXLoader

XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader.

T1547.001
Registry Run Keys / Startup Folder
MalwareXLoader

XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start.

T1555.003
Credentials from Web Browsers
MalwareXLoader

XLoader can gather credentials from several web browsers.

T1685
Disable or Modify Tools
MalwareXLoader

XLoader loads a copy of NTDLL to evade hooks from security monitoring tools on this library. XLoader can add the path of its executable to the Microsoft Defender exclusion list.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.