XDSpy

First seen
2020-08-17 00:00:00
Malware type
downloader, credential-stealer
Family
Malware family
Last IoC activity
2026-06-17 04:06:18
Profile updated
2026-07-07 12:58:46

Targeted industries: government-and-public-sector

Targeted regions: country_code:by country_code:ru country_code:ua country_code:ba

Context

According to ESET Research, XDDown is a primary malware component and is strictly a downloader. It persists on the system using the traditional Run key. It downloads additional plugins from the hardcoded C&C server using the HTTP protocol. The HTTP replies contain PE binaries encrypted with a hardcoded two-byte XOR key. Plugins include a module for reconnaissance on the affected system, crawling drives, file exfiltration, SSID gathering, and grabbing saved passwords.

Detection coverage

  • 4 YARA rules

Detection rules

  • HARFANGLAB_Xdspy_LNK_2025 (yara-rule)
  • HARFANGLAB_Xdspy_Etdownloader (yara-rule)
  • HARFANGLAB_Xdspy_Xdigo (yara-rule)
  • MALPEDIA_Win_Xdspy_Auto (yara-rule)

Reports & references

  • ESET — Xdspy Stealing Government Secrets Since 2011 (report)
  • vblocalhost.com — Vb2020 Faou Labelle (report)
  • github.com — Xdspy (report)
  • ESET — Eset Industry Report Government (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Xdspy (report)
  • harfanglab.io — Sadfuture Xdspy Latest Evolution (report)

External references