What is the Xlm.trojan.abracadabra.8.gen Trojan?

The name Xlm.trojan.abracadabra.8.gen is the designator and detection name given to a version of the Abracadabra Trojan.

This particular strain has been around for a few years now, first detected in mid-2020. The original campaign used to spread the malware was using a malicious encrypted Excel file. When a user attempted to open the malicious file, it decrypted itself using a default embedded password. The password string used was "VelvetSweatshop".

The reason for using an encrypted file is better threat detection avoidance. Anti-malware software cannot scan and detect the malicious payload inside the file while it exists in its encrypted state and the office application does not have access to the payload before the file is fully decrypted.

The Abracadabra Trojan has a number of malicious capabilities, including establishing persistence and communicating with the C2 server to download further malicious files.

The campaign spreading the Abracadabra Trojan used malicious spam emails tailored to look like overdue invoices sent to victims.

July 6, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.