Zscaler Threatlabz. (2025, January 27). Technical Analysis of Xloader Versions 6 and 7 | Part 1. Retrieved March 11, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareXLoader | XLoader features encrypted functions using the RC4 algorithm and bytecode operations. |
| T1055.004 Asynchronous Procedure Call |
MalwareXLoader | XLoader injects code into the APC queue using `NtQueueApcThread` API. |
| T1055.012 Process Hollowing |
MalwareXLoader | XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory. |
| T1106 Native API |
MalwareXLoader | XLoader uses the native Windows API for functionality, including defense evasion. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareXLoader | XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareXLoader | XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start. |
| T1555.003 Credentials from Web Browsers |
MalwareXLoader | XLoader can gather credentials from several web browsers. |
| T1685 Disable or Modify Tools |
MalwareXLoader | XLoader loads a copy of NTDLL to evade hooks from security monitoring tools on this library. XLoader can add the path of its executable to the Microsoft Defender exclusion list. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.