Cybercriminals use Eclipse Jarsigner to spread XLoader via ZIP files

XLoader malware campaign uses the DLL side-loading technique with the legitimate jarsigner application from the Eclipse Foundation to evade detection and distribute malicious software.

miércoles, 26 de febrero de 2025 • 1 min read • Q2BSTUDIO Team

Company-Software-Apps

A recent malware campaign has been identified distributing the XLoader malware through the DLL side-loading technique. This strategy leverages a legitimate application associated with the Eclipse Foundation to execute malicious code covertly.

According to the AhnLab Security Intelligence Center (ASEC), the application used in this attack is jarsigner, a file generated during the installation of the IDE package distributed by the Eclipse Foundation. By exploiting this legitimate component, attackers manage to evade security mechanisms and execute their malicious payload without raising suspicion.

At Q2BSTUDIO, we are committed to computer security and the development of robust technological solutions to protect companies and users from threats like this. Our team of experts constantly works on implementing advanced cybersecurity strategies to mitigate risks and strengthen our clients' digital infrastructure.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.