XDSpy
- First seen
- 2020-08-17 00:00:00
- Malware type
- downloader, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-06-17 04:06:18
- Profile updated
- 2026-07-07 12:58:46
Targeted industries: government-and-public-sector
Targeted regions: country_code:by country_code:ru country_code:ua country_code:ba
Context
According to ESET Research, XDDown is a primary malware component and is strictly a downloader. It persists on the system using the traditional Run key. It downloads additional plugins from the hardcoded C&C server using the HTTP protocol. The HTTP replies contain PE binaries encrypted with a hardcoded two-byte XOR key. Plugins include a module for reconnaissance on the affected system, crawling drives, file exfiltration, SSID gathering, and grabbing saved passwords.
Detection coverage
- 4 YARA rules
Detection rules
- HARFANGLAB_Xdspy_LNK_2025 (yara-rule)
- HARFANGLAB_Xdspy_Etdownloader (yara-rule)
- HARFANGLAB_Xdspy_Xdigo (yara-rule)
- MALPEDIA_Win_Xdspy_Auto (yara-rule)
Reports & references
- ESET — Xdspy Stealing Government Secrets Since 2011 (report)
- vblocalhost.com — Vb2020 Faou Labelle (report)
- github.com — Xdspy (report)
- ESET — Eset Industry Report Government (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Xdspy (report)
- harfanglab.io — Sadfuture Xdspy Latest Evolution (report)