Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The XRed backdoor also possesses worm-like USB propagation capabilities. It verifies the presence of an “autorun.inf” file on any inserted drive; if absent, it generates the file
This article highlights the identification of the XRed backdoor, its delivery using trojanized software... The trojanized version of Windows InstantView.exe drops Synaptics.exe payload
The malicious VBA script disables security warnings for VBA macros via the registry
Upon executing the trojanized binary, it downloads the legitimate copy of InstantView.exe from siliconmotion[.]com and launches it as a decoy... The payload contains the functionality to retrieve additional payload from the URLs that can be hardcoded in the binary.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan distributed through fake tax-themed phishing lures, enabling attacker access to victim systems.
Malware distributed via supply chain attack through compromised software downloads from a gaming peripheral vendor.
A backdoor delivered via a trojanized Windows InstantView.exe installer that drops Synaptics.exe, establishes persistence via a Registry Run key, collects system information, sends data over SMTP, supports keylogging and remote commands, propagates via USB using autorun.inf, and uses an embedded VBA script to infect XLSM files and disable macro security warnings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.