XDigo is a Go-based espionage malware associated with the XDSpy threat cluster, also known as Silent Werewolf. It has been observed in campaigns from at least March 2025 targeting government and government-affiliated entities in Eastern Europe and the CIS, with reporting also indicating interest in diplomatic, defense-related, finance, insurance, and public-sector organizations. The malware is used as a stealth-focused implant for intelligence collection rather than disruption.
XDigo is typically deployed through a multi-stage Windows intrusion chain involving crafted shortcut files delivered inside archive files. In documented operations, the shortcut launches a sequence that abuses DLL sideloading through a legitimate signed Microsoft executable to run a first-stage downloader commonly referred to as ETDownloader. That downloader establishes persistence via the Windows Startup mechanism, opens a decoy document, and retrieves or deploys the XDigo implant.
Once active, XDigo performs host reconnaissance and data collection. Reported capabilities include gathering system and user information, enumerating directories, identifying and collecting documents and archives of interest, capturing clipboard contents, taking screenshots, and executing commands or binaries received from command-and-control infrastructure. Collected data is staged into encrypted archives using AES-256-GCM before exfiltration. Command-and-control communications use HTTPS, and tasking has been described as protected with asymmetric cryptography for command confidentiality and authenticity verification. Multiple versions have been observed across 2023 to 2025, suggesting ongoing development and operational use.
Attribution to XDSpy is supported by recurring infrastructure patterns, shared infection mechanics, command structure similarities, and consistent regional government-focused targeting. XDigo fits the long-running XDSpy tradecraft of selective victim validation, stealthy persistence, and sustained data exfiltration from Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...opening a bogus attachment that's designed to exploit ZDI-CAN-25373, a vulnerability that has been put to use by multiple threat actors... It's officially tracked as CVE-2025-9491 (CVSS score: 7.0)"
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The primary persistence mechanism targets the Windows Startup folder, located at: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ %PROGRAMDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ The Windows Explorer shell automatically enumerates and executes all items within these directories during the user logon process.
T1547.009 Shortcut Modification is a technique in the MITRE ATT&CK framework under the Persistence tactic. It involves the modification of shortcuts (typically .lnk files) in Windows to achieve persistence by ensuring that malicious programs or scripts are executed whenever the user interacts with the shortcut.
The primary persistence mechanism targets the Windows Startup folder, located at: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ %PROGRAMDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ The Windows Explorer shell automatically enumerates and executes all items within these directories during the user logon process.
T1547.009 Shortcut Modification is a technique in the MITRE ATT&CK framework under the Persistence tactic. It involves the modification of shortcuts (typically .lnk files) in Windows to achieve persistence by ensuring that malicious programs or scripts are executed whenever the user interacts with the shortcut.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer used by XDSpy with selective payload delivery after victim validation.
An implant deployed for persistent data exfiltration operations following the downloader and DLL sideloading chain.
Go-based malware deployed via a multi-stage chain leveraging Windows LNK files; used against Eastern European government targets.
XDigo is a Go-based malware used by the XDSpy threat actor for cyber espionage, providing backdoor access and data theft capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.