XDSpy is malware referenced in the provided content as part of phishing-based intrusion activity. It is identified under the name XDSpy, with no additional aliases provided. The content associates XDSpy with the threat cluster Silent Werewolf, which has been active since at least 2011 and has targeted organizations in Russia, Belarus, Ukraine, Moldova, and Serbia. Silent Werewolf is described as using phishing lures to deliver malware such as XDSpy, XDigo, and DSDownloader. In March 2025 campaigns targeting Moldovan and Russian companies, the attacks were characterized by phishing emails carrying ZIP attachments with LNK files and nested ZIP archives; the broader delivery chain described for these campaigns involved DLL sideloading via DeviceMetadataWizard.exe and a C# loader named d3d9.dll, although the content specifically says these campaigns likely used XDigo as the payload rather than explicitly attributing that chain to XDSpy. The actor is reported to have targeted sectors including nuclear, aircraft, instrumentation, and mechanical engineering in Russia. No malware-family-specific capabilities, persistence mechanisms, command-and-control details, or indicators of compromise for XDSpy are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool referenced in the content without additional description.
Spyware used by the Silent Werewolf group for espionage, delivered via phishing lures to organizations in Eastern Europe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.