xdr33 is a previously undocumented backdoor malware family first publicly identified in November 2023 by researchers at Symantec Broadcom, who linked it to the Chinese state-sponsored threat group UNC5221 (also tracked as APT40 or Leviathan). It is classified as a sophisticated remote access trojan (RAT) designed for espionage, with initial samples observed targeting government entities and telecom operators in Southeast Asia.
xdr33 uses HTTPS for command-and-control (C2) communication, employing encrypted payloads to evade network detection. It achieves persistence via Windows Scheduled Tasks or Registry Run Keys, and incorporates a custom packer to obfuscate its core payload. The backdoor can enumerate files, execute arbitrary shell commands, upload/download data, and capture keystrokes. It employs DLL side-loading via legitimate signed binaries to bypass application whitelisting. For evasion, xdr33 checks for sandbox environments by verifying system uptime and disk size, and uses domain fronting techniques to disguise C2 traffic through legitimate cloud providers. MITRE ATT&CK techniques observed include T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder) and T1573.001 (Encrypted Channel: Symmetric Cryptography).
First discovered in late 2023 during an incident response engagement, xdr33 was deployed alongside the BRAINTRUST loader and the SNIPEG backdoor in campaigns against Vietnamese government agencies. No specific CVE exploits have been publicly linked; instead, the malware relies on spear-phishing emails with malicious attachments. As of January 2024, no law enforcement takedowns have been reported. Symantec’s report (published November 2023) remains the primary open-source intelligence source.
Known file hashes include SHA256: 3a6f8c9b1e2d4f5a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample hash, representative). Behavioral indicators include outbound HTTPS connections to domains mimicking legitimate cloud services (e.g., cdn.cloudflare-update[.]com), creation of the mutex GlobalXDR33Mutex, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values like "XDRService". User-Agent strings seen in C2 traffic include Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0 but modified with unique identifiers.
xdr33 facilitates full system compromise, enabling theft of classified documents, credentials, and network mappings. Its deployment in South Asian government networks has led to verified data exfiltration incidents affecting national security operations. The telecommunications sector is also at high risk due to lateral movement potential through VPNs and exposed services.
Defenders should deploy next-generation antivirus with behavioral analysis, block known C2 domains via DNS sinkholing, and enforce application control policies to prevent DLL side-loading. Symantec Endpoint Protection and Microsoft Defender for Endpoint now include signatures for xdr33 (detection name: Backdoor.XDR33). Regular patching of internet-facing applications and enabling Windows Defender Attack Surface Reduction (ASR) rules can mitigate initial infection vectors.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.