ATT&CKReferencesNetskope XLoader 2022

Netskope XLoader 2022

Gustavo Palazolo, Netskope. (2022, March 11). New Formbook Campaign Delivered Through Phishing Emails. Retrieved March 11, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareXLoader

XLoader uses various packers, including CyaX, to obfuscate malicious executables.

T1053.005
Scheduled Task
MalwareXLoader

XLoader can create scheduled tasks for persistence.

T1113
Screen Capture
MalwareXLoader

XLoader can capture screenshots on compromised hosts.

T1115
Clipboard Data
MalwareXLoader

XLoader can collect data stored in the victim's clipboard.

T1203
Exploitation for Client Execution
MalwareXLoader

XLoader has exploited Office vulnerabilities during local execution such as CVE-2017-11882 and CVE-2018-0798.

T1555
Credentials from Password Stores
MalwareXLoader

XLoader can collect credentials stored in email clients.

T1555.003
Credentials from Web Browsers
MalwareXLoader

XLoader can gather credentials from several web browsers.

T1685
Disable or Modify Tools
MalwareXLoader

XLoader loads a copy of NTDLL to evade hooks from security monitoring tools on this library. XLoader can add the path of its executable to the Microsoft Defender exclusion list.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.