typeentityconfidencehighcreated2026-08-24updated2026-08-24malware-familyinfostealerloaderscriptdefense-evasionexecutionpersistencec2

xloader

Commodity Windows infostealer family, historically a fork of Formbook. XLoader is typically delivered via macro-enabled documents, JavaScript droppers, or batch-script loaders. It employs multi-stage decryption (AES, XOR, custom ciphers) and commonly injects its final payload into trusted developer utilities such as MSBuild.exe or aspnet_compiler.exe to evade application-control policies.

Build Stack Typically Observed

  • Outer layer: Batch script, JScript, or Office macro carrier. ^[/intel/analyses/5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed.html]
  • Decryption chain: AES-256-CBC + rolling XOR + custom ciphers (e.g., seeded rail-fence). ^[inner.ps1]
  • Inner payload: .NET Framework DLL obfuscated with CryptoObfuscator or ConfuserEx. ^[rabin2-info.txt]
  • Injection target: MSBuild.exe, aspnet_compiler.exe, or other trusted .NET utilities. ^[inner.ps1:112]
  • Builder artifacts: Developer PDB paths, benign-themed namespace masquerade (e.g., DigitalAudioForge.Processing). ^[rabin2-info.txt]

Deploy / TTPs Typically Observed

  • T1059.001 — PowerShell: Hidden-window execution for payload staging. ^[/intel/analyses/5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed.html]
  • T1059.003 — Windows Command Shell: Batch self-launch and extraction. ^[file.txt]
  • T1027.002 — Obfuscated Files or Information: Multi-layer encryption and custom ciphers. ^[inner.ps1]
  • T1055 — Process Injection: Reflective .NET assembly load into trusted process. ^[inner.ps1:97,127]
  • T1127.001 — Trusted Developer Utilities Proxy Execution: MSBuild.exe target. ^[inner.ps1:112]
  • T1053.005 — Scheduled Task/Job: Logon-triggered persistence. ^[payload.bat:35]
  • T1547.001 — Boot or Logon Autostart Execution: File copy to AppData. ^[payload.bat:22-23]
  • T1564.003 — Hide Artifacts: Hidden Window: FreeConsole(), ShowWindow. ^[inner.ps1:102-104]

Variants / Aliases

  • XLoader (primary)
  • Formbook (historically related codebase fork)

Notable Analyses

  • 5a26fd46 — Three-tier batch→PowerShell→.NET dropper with AES/rail-fence payload and MSBuild proxy injection. Filename LX_2026815111.bat, compiled May 2026. ^[/intel/analyses/5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed.html]

Capabilities

  • aes-256-cbc-payload-decryption
  • rolling-xor-payload-layer
  • rail-fence-seeded-cipher
  • cryptoobfuscator-dotnet-obfuscation
  • msbuild-proxy-injection
  • audio-themed-namespace-masquerade
  • scheduled-task-persistence-logon
  • appdata-local-studio-persistence
  • self-delete-guard-string-list
  • powershell-cmd-hidden-relaunch
  • reflective-dotnet-assembly-load
  • console-window-hiding-pinvoke

Related