Skip to content

Spyware

XDSpy

According to ESET Research, XDDown is a primary malware component and is strictly a downloader.

XDSpy is a Windows spyware.

Background

ESET Research notes that XDDown is the core malware component and functions purely as a downloader. It maintains persistence through the conventional Run key. Over HTTP, it retrieves further plugins from a hardcoded C&C server, with the responses delivering PE binaries that are encrypted using a hardcoded two-byte XOR key. The available plugins handle tasks such as reconnaissance of the infected host, crawling drives, exfiltrating files, collecting SSIDs, and stealing saved passwords.


Source: Malpedia (Fraunhofer FKIE).