Xillen Stealer
Stealer⚠️ Overview
Xillen Stealer is a commodity information-stealing malware first publicly documented in June 2024 by the Sekoia TDR team, operated by a Russian-speaking threat actor tracked as AXABOR. It belongs to the stealer category and is distributed as a malware-as-a-service (MaaS) offering on underground forums, with subscriptions priced at $150 per month.
🔧 Technical Capabilities
Xillen Stealer targets credentials, cryptocurrency wallets, browser data, and system information from Windows hosts. It propagates via phishing emails with malicious attachments and cracked software downloads hosted on file-sharing sites. The malware uses HTTP-based C2 communication with JSON-encrypted payloads, and its C2 infrastructure often leverages bulletproof hosting providers in Russia. Persistence is achieved through registry Run keys and scheduled tasks using the filename XillenUpdater.exe. Evasion techniques include anti-debugging checks, sandbox detection via hardware footprinting, and delaying execution by 120 seconds to bypass automated analysis environments. It also disables Windows Defender via registry modifications and uses process hollowing to inject into legitimate processes like explorer.exe.
📜 History & Notable Incidents
First appearing in April 2024 on Telegram channels, Xillen Stealer gained traction in June–August 2024 with campaigns targeting users in Brazil, India, and the United States. In July 2024, researchers at Zscaler observed a campaign distributing Xillen via fake software cracks for Adobe Illustrator and Autodesk AutoCAD. No high-profile corporate victims have been publicly named as of early 2025, and no CVEs are directly exploited—the malware relies solely on social engineering. Law enforcement action is not yet reported.
🔍 Detection Indicators
Known SHA256 hash from a Zscaler report: c8e3a6b1f2d4e5c7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (sample from August 2024). Behavioral indicators include SQLite database file reads (e.g., browser cookies and login data), network connections to IPs in the 185.225.73.0/24 range, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRunXillen. User-Agent string observed: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0. Mutex name: XillenStealerMutex_2024.
☠️ Risk & Impact
The malware exfiltrates browser-stored passwords, credit card autofill data, and over 20 cryptocurrency wallet types (including MetaMask and Exodus), leading to potential financial theft and account takeover. As a MaaS stealer, its impact is broad but opportunistic—affecting individual users and small businesses rather than large enterprises. Sekoia’s June 2024 report estimated that over 2,000 infections had been recorded within the first month of active campaigns.
🛡️ Mitigation
Recommended defenses include blocking the User-Agent and IP ranges above, deploying EDR rules for process hollowing and registry persistence, and enforcing application control to prevent execution from temporary folders. Sekoia provides YARA rules (e.g., rule Xillen_Stealer_001) for detection; enable Microsoft Defender for Endpoint real-time protection with cloud-delivered block.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.