HomeSecurityBotnet XLoader: Hides its servers using probability theory

XLoader Botnet: Hides its servers using probability theory

Threat analysts have identified a new version of the XLoader botnet malware that uses probability theory to hide its servers, making it difficult to stop the malware from operating.

This helps malware operators continue to use the same infrastructure without the risk of losing nodes due to blocking of identified IP addresses, while also reducing the chances of tracking and identification.

The XLoader botnet is an information-stealing program originally based on Formbook , targeting Windows and macOS operating systems . It first began widespread deployment in January 2021.

See also: ChromeLoader: The new malware that modifies browser settings

Researchers at CheckPoint, who have been monitoring the evolution of malware, sampled and analyzed the most recent versions 2.5 and 2.6 of XLoader and identified some critical differences compared to previous versions.

The XLoader botnet has already camouflaged its real command and control (C2) servers in version 2.3 by hiding the real domain name in a configuration that includes 63 decoys.

XLoader Botnet: Hides its servers using probability theory
XLoader Botnet: Hides its servers using probability theory

In more recent versions, however, CheckPoint analysts observed that the XLoader botnet replaces 8 out of a list of 64 randomly selected domains in its configuration list with new values ​​on each communication attempt.

XLoader Botnet: Hides its servers using probability theory
XLoader Botnet: Hides its servers using probability theory

"If the actual C&C domain appears in the second part of the list, it is accessed in each cycle approximately once every 80-90 seconds. If it appears in the first part of the list, it will be replaced by another random domain name," CheckPoint explains.

"The 8 domains that replace the first part of the list are chosen randomly and the real C&C domain can be one of them. In this case, the probability of accessing a real C&C domain in the next cycle is 7/64 or 1/8 depending on the position of the fake c2(2) domain."

See also: EnemyBot malware: Exploits critical VMware, F5 BIG-IP bugs

This helps conceal the actual C2 servers from security analysts, while keeping the impact on the XLoader botnet malware's operations to a minimum.

Successful access to C2 results from the law of large numbers, which increases the chances of achieving the expected result with several trials.

As CheckPoint explains via the table below, threat analysts would have to perform a lengthy simulation to extract the actual C2 address, which is an atypical practice and renders all automated scripts useless.

XLoader Botnet: Hides its servers using probability theory
XLoader Botnet: Hides its servers using probability theory

At the same time, for malware operators, it would be unlikely that the XLoader botnet would not contact the authentic C2 address an hour after infection.

In version 2.6, CheckPoint observed that the XLoader botnet removed this functionality from the 64-bit of the payload, where the malware contacts the real C2 domain every time. However, on 32-bit, which are very common in sandboxes hosted by virtual machines and used by threat analysts, the XLoader botnet retains the C2 obfuscation.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS