HomeSecurityXLoader malware analyzed with the help of ChatGPT

XLoader malware analyzed with the help of ChatGPT

XLoader remains one of the most dangerous malware families facing cybersecurity researchers. This sophisticated information-stealing loader emerged in 2020 as a rebrand of FormBook and has evolved into an increasingly sophisticated threat.

XLoader malware analyzed with the help of ChatGPT

The malware code is decrypted only at runtime and is protected behind multiple layers of encryption, each locked with different keys hidden throughout the binary. Even automated sandbox analysis tools struggle to cope with XLoader's aggressive evasion techniques, which block malicious execution when virtual environments are detected.

See also: Malicious ads for PuTTY and Teams distribute malware

XLoader analysis with the help of generative AI (ChatGPT)

Check Point researchers identified a novel approach to analyzing XLoader, leveraging generative AI . The latest sample of XLoader version 8.0 presented significant obstacles with custom encryption schemes, obfuscated API calls, and extensive sandbox evasion techniques. The malware’s creators release new versions regularly, changing internal mechanisms and adding anti-analysis methods that render previous research inadequate.

XLoader malware analyzed with the help of ChatGPT

The research showed how ChatGPT accelerated static reverse engineering from days to hours. By extracting the contents of the database and analyzing them using cloud-based artificial intelligence, the researchers showed that deep analysis could proceed without maintaining live disassembler sessions. This approach reduced the need for reliance on heavy local tools, with results that could be more easily reproduced and shared.

See also: Open VSX: Addresses Token Leaks and Malicious Extensions

What the data showed for XLoader version 8.0

XLoader version 8.0 implements advanced protection mechanisms through a built-in crypter that hides the main payload in two rounds of RC4 encryption. The first layer applies RC4 decryption to the entire buffer, followed by a second pass that processes 256-byte chunks using a different key. Each encryption round requires specific keys derived through complex algorithms spread across multiple operations.

Check Point analysts noted that the main payload is subjected to this two-layer encryption scheme, with Stage-1 and Stage-2 keys being calculated through separate generation processes.

See also: New TruffleNet BEC campaign leverages AWS SES

XLoader malware analyzed with the help of ChatGPT

The Stage-1 key (20EBC3439E2A201E6FC943EE95DACC6250A8A647) and Stage-2 key (86908CFE6813CB2E532949B6F4D7C6E6B00362EE) were successfully extracted through AI analysis combined with debugging validation during execution. The full decompression process, which traditionally consumes days of manual reverse engineering, was compressed to approximately 40 minutes, providing defenders with fresher indicators of compromise.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS