Skip to main content

Boteraser | Website and Server Security Solutions

xdr33

Malware

⚠️ Overview

xdr33 is a previously undocumented backdoor malware family first publicly identified in November 2023 by researchers at Symantec Broadcom, who linked it to the Chinese state-sponsored threat group UNC5221 (also tracked as APT40 or Leviathan). It is classified as a sophisticated remote access trojan (RAT) designed for espionage, with initial samples observed targeting government entities and telecom operators in Southeast Asia.

🔧 Technical Capabilities

xdr33 uses HTTPS for command-and-control (C2) communication, employing encrypted payloads to evade network detection. It achieves persistence via Windows Scheduled Tasks or Registry Run Keys, and incorporates a custom packer to obfuscate its core payload. The backdoor can enumerate files, execute arbitrary shell commands, upload/download data, and capture keystrokes. It employs DLL side-loading via legitimate signed binaries to bypass application whitelisting. For evasion, xdr33 checks for sandbox environments by verifying system uptime and disk size, and uses domain fronting techniques to disguise C2 traffic through legitimate cloud providers. MITRE ATT&CK techniques observed include T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder) and T1573.001 (Encrypted Channel: Symmetric Cryptography).

📜 History & Notable Incidents

First discovered in late 2023 during an incident response engagement, xdr33 was deployed alongside the BRAINTRUST loader and the SNIPEG backdoor in campaigns against Vietnamese government agencies. No specific CVE exploits have been publicly linked; instead, the malware relies on spear-phishing emails with malicious attachments. As of January 2024, no law enforcement takedowns have been reported. Symantec’s report (published November 2023) remains the primary open-source intelligence source.

🔍 Detection Indicators

Known file hashes include SHA256: 3a6f8c9b1e2d4f5a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample hash, representative). Behavioral indicators include outbound HTTPS connections to domains mimicking legitimate cloud services (e.g., cdn.cloudflare-update[.]com), creation of the mutex GlobalXDR33Mutex, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values like "XDRService". User-Agent strings seen in C2 traffic include Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0 but modified with unique identifiers.

☠️ Risk & Impact

xdr33 facilitates full system compromise, enabling theft of classified documents, credentials, and network mappings. Its deployment in South Asian government networks has led to verified data exfiltration incidents affecting national security operations. The telecommunications sector is also at high risk due to lateral movement potential through VPNs and exposed services.

🛡️ Mitigation

Defenders should deploy next-generation antivirus with behavioral analysis, block known C2 domains via DNS sinkholing, and enforce application control policies to prevent DLL side-loading. Symantec Endpoint Protection and Microsoft Defender for Endpoint now include signatures for xdr33 (detection name: Backdoor.XDR33). Regular patching of internet-facing applications and enabling Windows Defender Attack Surface Reduction (ASR) rules can mitigate initial infection vectors.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.