Skip to content

Malware

PocoDown

aka Blitz · PocoDownloader

uses POCO C++ cross-platform library, Xor-based string obfuscation, SSL library code and string overlap with Xtunnel, infrastructure overlap with X-Agent, probably in use since mid-2018

PocoDown, also known as Blitz, PocoDownloader, is a Windows malware family operated by APT28.

Background

Relies on the cross-platform POCO C++ library and obfuscates its strings with XOR. It shares SSL library code and string overlaps with Xtunnel as well as infrastructure overlap with X-Agent, and has likely been active since mid-2018.


Source: Malpedia (Fraunhofer FKIE).