Xbash is a cross-platform malware family associated with opportunistic attacks against Linux and Windows systems, with particular notoriety for targeting exposed database and server environments. It has been observed combining multiple criminal functions, including ransomware-style encryption and network reconnaissance, and has been linked to campaigns seeking to monetize compromised infrastructure through extortion. On compromised systems, Xbash can gather local network information such as IP addressing and intranet details, perform TCP and UDP port scanning, and retrieve updated command-and-control information from online resources. Its execution tradecraft includes abuse of native Windows utilities and scripting engines, including PowerShell, mshta, and regsvr32, as well as execution of malicious JavaScript and VBScript payloads. On Windows, it can establish persistence through Startup-folder mechanisms. The malware’s behavior reflects a blend of reconnaissance, payload staging, execution, persistence, and extortion-oriented activity against internet-exposed enterprise assets, especially database systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Cobalt Group has used regsvr32.exe to execute scripts. Saint Bot has used regsvr32 to execute scripts. Xbash can use regsvr32 for executing scripts.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
"...leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website." / "...has exploited client software vulnerabilities for execution..." / "...has used multiple software exploits for common client software...to gain code execution."
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
APT29 has use mshta to execute malicious scripts on a compromised host... APT32 has used mshta.exe for code execution... APT38 has used a renamed version of mshta.exe to execute malicious HTML files... FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.
“Sandworm Team deployed CaddyWiper…to wipe files…along with mapped drives, and physical drive partitions… AcidPour…perform an in-depth wipe…through either data overwrite or calling various IOCTLS… AcidRain performs an in-depth wipe… Apostle…data destruction tool… writes random data… resizing… deleting… BlackEnergy 2 contains a ‘Destroy’ plug-in… overwriting file contents… HermeticWiper… recursively wipe folders and files… Industroyer’s data wiper module clears registry keys and overwrites… KillDisk deletes system files to make the OS unbootable… Shamoon attempts to overwrite operating system files and disk structures… WhisperGate… corrupt files by overwriting…”
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as ransomware in the context of prior research/simulation involving Elasticsearch exposure; not the main subject of this piece.
Can execute malicious VBScript payloads on victim machines.
Collects IP addresses and local intranet information from victim machines.
Malware that invokes PowerShell to download malicious PE executables or DLLs for execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.