PULSE NAME
From Credit Card Skimming to Exploiting Zero-Days
WHITE XE Group AlienVault 2025-02-03 Modified: 2025-03-05
31
IOCs
MEDIUM VOLUME
XE Group, a cybercriminal organization active since 2013, has evolved from credit card skimming to exploiting zero-day vulnerabilities. The group initially focused on web vulnerabilities and supply chain attacks but has now shifted to targeted information theft in manufacturing and distribution sectors. They have demonstrated increased sophistication by exploiting previously undocumented vulnerabilities in VeraCore software, including an SQL injection flaw and an upload validation vulnerability. XE Group maintains long-term access to compromised systems, as evidenced by their reactivation of a webshell planted years earlier. Their recent activities involve exfiltrating config files, network reconnaissance, and deploying a Remote Access Trojan using obfuscated PowerShell commands. The group's evolution highlights their adaptability and growing threat to supply chain security.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
ASPXSpy - S0073 ASPXTool Meterpreter
Indicators of Compromise (31)
All FileHash-SHA256 FileHash-SHA1 CVE FileHash-MD5 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 680b7e8ec8204975c5026bcbaf70f7e9620eacdd7bf72e5476d17266b4a7d316 2025-02-03
FileHash-SHA1 04fb442ba598bbe02fd2164132d63355078e5f52 2025-02-03
FileHash-SHA1 0c7b8771bde499f1af55358206290fbc5cfba545 2025-02-03
CVE CVE-2017-9248 2025-02-03
CVE CVE-2019-18935 2025-02-03
CVE CVE-2024-57968 2025-02-03
CVE CVE-2025-25181 2025-02-03
FileHash-MD5 339a79457a8cf3504312d394be3ece98 2025-02-03
FileHash-MD5 457d7e3a708d1b5c6a8d449e52064985 2025-02-03
FileHash-MD5 7a9b5c3bb7dab0857ee2c2d71758eca3 2025-02-03
FileHash-MD5 7abb73b7844f2308d9c62954e6e8b7fc 2025-02-03
FileHash-MD5 7b5b7d96006fec70c2091e90fbf02b99 2025-02-03
FileHash-MD5 cb424b3be3cb35ec1349bd3e09c53cc4 2025-02-03
FileHash-SHA1 032dd95a1299f37aaa76318945e030eb7da94da9 2025-02-03
FileHash-SHA1 16db01fe25b0c09e18d13f38c88a4ead5d10e323 2025-02-03
FileHash-SHA1 84e7f4ff1f93a4297c2e2c4e54f14edb18396b60 2025-02-03
FileHash-SHA1 9e928a26aa3c0e6eb8e709fc55ea12dcf7e02ff9 2025-02-03
FileHash-SHA1 ede5ddb97b98d80440553b23dfc19fdb4adc7499 2025-02-03
FileHash-SHA256 013ccea1d7fc2aa2d660e900f87a3192f5cb73768710ef2eb9016f81df8e5c70 2025-02-03
FileHash-SHA256 322f8cd560d5e10e93af3ea6d3505c8de213f549e6627c3ef4664ed92ba55f56 2025-02-03
FileHash-SHA256 38b2d52dc471587fb65ef99c64cb3f69470ddfdaa184a256aecb26edeff3553a 2025-02-03
FileHash-SHA256 884c394c7b3eb757ae57050ac2e6a75385a361555e8e4272de1a3cf24746eec7 2025-02-03
FileHash-SHA256 ba2109b5a3ccebbc494ee93880b55640539c7d25b85bc12189f0c671ce473771 2025-02-03
FileHash-SHA256 c564acd69efa62a5037931090bf70a6506419fdf59ec52f8d1ab0b15d861cc67 2025-02-03
URL https://hivnd.com/software/7z.exe 2025-02-03
domain hivnd.com 2025-02-03
domain object.fm 2025-02-03
domain paycashs.com 2025-02-03
domain sexadult.com 2025-02-03
domain xegroups.com 2025-02-03
domain xework.com 2025-02-03