The road to Xloader
Introduction
Xloader is a stealer that was built on the FormBook malware family that first emerged in 2016; the rebranded Xloader was introduced in 2020. It is highly sophisticated malware that uses a combination of anti-analysis and obfuscation techniques, and it’s written in pure assembly, so there are minimal compiler artifacts.
The infection chain used in this campaign is widely used to deliver multiple different malware families in a very similar way, with almost identical loader characteristics.










