Xbash
MITRE ATT&CK: S0341 View on attack.mitre.org
Aliases: Xbash
- Malware type
- ransomware, cryptominer, worm
- Family
- Malware family
- Operating systems
- windows, linux
- Related IoCs
- 2 (1 malicious)
- Last IoC activity
- 2025-11-25 03:43:03
- Profile updated
- 2026-07-07 12:56:24
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
Xbash is a malware family that has targeted Linux and Microsoft Windows servers. The malware has been tied to the Iron Group, a threat actor group known for previous ransomware attacks. Xbash was developed in Python and then converted into a self-contained Linux ELF executable by using PyInstaller.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Xbash (S0341). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | http://211.252.152.47/js/lw.txt | 2025-11-25 | 2 |
Detection coverage
- 469 Sigma rules
Malware & tools used
- Web Protocols (attack-pattern)
- Data Destruction (attack-pattern)
- Visual Basic (attack-pattern)
- Mshta (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Cron (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- PowerShell (attack-pattern)
- JavaScript (attack-pattern)
- Network Service Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Password Guessing (attack-pattern)
- Regsvr32 (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Dead Drop Resolver (attack-pattern)
Reports & references
- Palo Alto Unit 42 — Agedlibra (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Xbash (report)
- researchcenter.paloaltonetworks.com — Unit42 Xbash Combines Botnet Ransomware Coinmining Worm Targets Linux Windows (report)
- MITRE ATT&CK — S0341 (report)