xloader
Commodity Windows infostealer family, historically a fork of Formbook. XLoader is typically delivered via macro-enabled documents, JavaScript droppers, or batch-script loaders. It employs multi-stage decryption (AES, XOR, custom ciphers) and commonly injects its final payload into trusted developer utilities such as MSBuild.exe or aspnet_compiler.exe to evade application-control policies.
Build Stack Typically Observed
- Outer layer: Batch script, JScript, or Office macro carrier. ^[/intel/analyses/5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed.html]
- Decryption chain: AES-256-CBC + rolling XOR + custom ciphers (e.g., seeded rail-fence). ^[inner.ps1]
- Inner payload: .NET Framework DLL obfuscated with CryptoObfuscator or ConfuserEx. ^[rabin2-info.txt]
- Injection target:
MSBuild.exe,aspnet_compiler.exe, or other trusted .NET utilities. ^[inner.ps1:112] - Builder artifacts: Developer PDB paths, benign-themed namespace masquerade (e.g.,
DigitalAudioForge.Processing). ^[rabin2-info.txt]
Deploy / TTPs Typically Observed
- T1059.001 — PowerShell: Hidden-window execution for payload staging. ^[/intel/analyses/5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed.html]
- T1059.003 — Windows Command Shell: Batch self-launch and extraction. ^[file.txt]
- T1027.002 — Obfuscated Files or Information: Multi-layer encryption and custom ciphers. ^[inner.ps1]
- T1055 — Process Injection: Reflective .NET assembly load into trusted process. ^[inner.ps1:97,127]
- T1127.001 — Trusted Developer Utilities Proxy Execution:
MSBuild.exetarget. ^[inner.ps1:112] - T1053.005 — Scheduled Task/Job: Logon-triggered persistence. ^[payload.bat:35]
- T1547.001 — Boot or Logon Autostart Execution: File copy to AppData. ^[payload.bat:22-23]
- T1564.003 — Hide Artifacts: Hidden Window:
FreeConsole(),ShowWindow. ^[inner.ps1:102-104]
Variants / Aliases
- XLoader (primary)
- Formbook (historically related codebase fork)
Notable Analyses
5a26fd46— Three-tier batch→PowerShell→.NET dropper with AES/rail-fence payload and MSBuild proxy injection. FilenameLX_2026815111.bat, compiled May 2026. ^[/intel/analyses/5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed.html]
Capabilities
aes-256-cbc-payload-decryptionrolling-xor-payload-layerrail-fence-seeded-ciphercryptoobfuscator-dotnet-obfuscationmsbuild-proxy-injectionaudio-themed-namespace-masqueradescheduled-task-persistence-logonappdata-local-studio-persistenceself-delete-guard-string-listpowershell-cmd-hidden-relaunchreflective-dotnet-assembly-loadconsole-window-hiding-pinvoke
Related
- formbook — Historical codebase fork
- msbuild-proxy-execution — Procedure page for MSBuild abuse
- rail-fence-cipher-payload-obfuscation — Technique page for seeded rail-fence cipher
- audio-themed-namespace-masquerade — Technique page for benign namespace disguise