216.73.217.22

Latest Xloader Obfuscation Methods and Network Protocol

· Published 01/04/2026 15:17 · Modified 01/04/2026 19:28

Export JSON

Essential information

Published
01/04/2026 15:17
Modified
01/04/2026 19:28
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
ftp infostealer wininet api xloader
Tags
2026-04-01 ftp infostealer wininet api xloader
Related entities
3 indicators, 3 observables, 3 techniques (mitre)

Description

is an information stealing malware family that evolved from Formbook and targets web browsers, email clients, and File Transfer Protocol () applications. Additionally, may execute arbitrary commands and download second-stage payloads on an infected system. The author of continues to update the codebase, with the most recent observed version being 8.7. Since version 8.1, the developer applied several changes to the code obfuscation. The purpose of this blog is to describe the latest obfuscation methods and provide an in-depth analysis of the network communication protocol. We highly recommend reading our previous blogs about in order to get a better understanding of the malware’s internals.

External references