XE Group is a cybercriminal threat actor associated with exploitation of internet-facing enterprise applications for information theft and persistent access. The group has been linked to exploitation of Progress Telerik UI for ASP.NET AJAX and Advantive VeraCore, including zero-day activity against supply-chain management software. Reported operations show XE Group conducting reconnaissance and scanning prior to exploitation, then using vulnerable IIS-hosted applications to upload and execute malicious payloads, deploy webshells such as ASPXSpy, and establish backdoor access. In Telerik-related intrusions affecting U.S. federal civilian executive branch environments, XE Group was identified as a distinct cybercriminal actor exploiting CVE-2019-18935 for remote code execution. The actor uploaded malicious DLL payloads and executed them through the IIS worker process, and its tooling included reverse-shell capability and the ability to decode and deploy an ASPX webshell. In VeraCore intrusions, XE Group was attributed with chaining CVE-2024-57968 and CVE-2025-25181 to upload ASPXSpy webshells, gain control over vulnerable applications, and access or manipulate backend data. Activity attributed to the group indicates a focus on post-compromise persistence, defense evasion, and data access rather than disruptive or destructive effects. Observed tradecraft includes reconnaissance, scanning, exploitation of public-facing applications, webshell deployment, malicious DLL execution, backdoor establishment, and theft of information from compromised systems and databases. Available reporting supports a financially motivated cybercrime profile. No high-confidence country of origin is established in the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Analysts determined that multiple cyber threat actors, including an advanced persistent threat (APT) actor, were able to exploit a .NET deserialization vulnerability (CVE-2019-18935) in Progress Telerik user interface (UI) for ASP.NET AJAX, located in the agency’s Microsoft Internet Information Services (IIS) web server. Successful exploitation of this vulnerability allows for remote code execution.
CVE-2024-57968 (CVSS skóre 9,9) Kritická zero-day zraniteľnosť Advantive VeraCore umožňuje vzdialeným autentifikovaným útočníkom útok typu path traversal a nahrávanie súborov do priečinkov, ktoré na to neboli určené.
CVE-2025-25181 (CVSS skóre 5,8) Zero-day zraniteľnosť v komponente timeoutWarning.asp umožňuje vzdialeným neautentifikovaným útočníkom zneužiť parameter PmSess1 pre vykonávanie ľubovoľných príkazov SQL.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Supply-chain-oriented intrusions leveraging zero-day vulnerabilities in third-party software to enable information theft.
Cybercrime activity exploiting VeraCore (including zero-day) and other product flaws to deploy reverse shells/web shells and maintain persistent access.
XE Group is actively exploiting two VeraCore zero-day vulnerabilities in a chained attack to upload ASPXSpy webshells and establish backdoor access to vulnerable systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.