XBTL

First seen
2022-04-15 00:00:00
Malware type
rat, spyware
Profile updated
2026-07-07 15:26:45

Targeted industries: financial-services government-and-public-sector manufacturing

Context

XBTL is a remote access trojan (RAT) primarily focusing on data exfiltration from compromised systems. It has been observed targeting sectors such as financial services, government, and manufacturing, with versatile capabilities for espionage.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Xbtl_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Xbtl (report)

External references