Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

One of the most devious malware strains might have been cracked – and it’s all thanks to Gen AI

Tech Wavo by Tech Wavo
November 4, 2025
in Computers
0



  • Check Point used GenAI to semi-automate reverse engineering of the evasive XLoader infostealer
  • AI decrypted code, revealed APIs, and uncovered 64 hidden C2 domains and sandbox evasion tricks
  • XLoader evolved from Formbook; AI boosts analysis speed but doesn’t replace human malware analysts

Cybersecurity researchers from Check Point Research may have just cracked one of the most devious malware families to have ever existed, thanks to Generative Artificial Intelligence (GenAI).

In a new blog post, the researchers explained how analyzing malware is a slow, manual process that requires researchers to “unpack binaries, trace functions, and build decryption scripts”. Analyzing XLoader – an infamous infostealer that’s been around for roughly half a decade – is even more difficult, because it cannot be sandboxed.

That’s when Check Point turned to AI for assistance. Using ChatGPT, the researchers combined two complementary workflows: cloud-based static analysis, and MCP-assisted runtime analysis. The first exports data from IDA Pro and lets the AI analyze it in the cloud. “The model identified encryption algorithms, recognized data structures, and even generated Python scripts to decrypt sections of code,” the researchers explained.


You may like

Unpacking XLoader

The second connected the AI to a live debugger to extract runtime values such as encryption keys, decrypted buffers, and in-memory C2 data. “This hybrid AI workflow turned tedious manual reverse engineering into a semi-automated process that’s faster, repeatable, and easy to share across teams.”

Check Point was impressed with the results. They claim to have decrypted core code, revealed encryption layers, unmasked hidden APIs, recovered 64 hidden C2 domains, and discovered a new sandbox evasion mechanism called “secure-call trampoline”.

In short, AI helped unpack how XLoader hides, communicates, and protects itself, which is crucial information in the fight against infections. Still, Check Point stressed that despite the great work, AI “doesn’t replace malware analysts” but rather “supercharges” them with speed, reproducibility, insight, and defense.

Earliest records of XLoader date back to 2021, when Check Point Research saw it in the wild, stealing data from MacOS users. It evolved from the infamous Formbook malware that, at the time, was active for over five years. While Formbook was initially created to be a simple keylogger, it was upgraded and rebranded as XLoader. Formbook was used to primarily target Windows users.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!


Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Previous Post

UK High Court sides with Stability AI over Getty in copyright case

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

One of the most devious malware strains might have been cracked – and it’s all thanks to Gen AI

by Tech Wavo
November 4, 2025
0
Building a security-first framework against evolving cyberthreats
Computers

Check Point used GenAI to semi-automate reverse engineering of the evasive XLoader infostealerAI decrypted code, revealed APIs, and uncovered 64...

Read more

UK High Court sides with Stability AI over Getty in copyright case

by Tech Wavo
November 4, 2025
0
UK High Court sides with Stability AI over Getty in copyright case
Computers

Stability AI has partially succeeded in defending itself against accusations of copyright infringement. As reported by The Guardian, Stability AI...

Read more

Here’s What Azteca Stadium Will Look Like for the 2026 World Cup

by Tech Wavo
November 4, 2025
0
Here’s What Azteca Stadium Will Look Like for the 2026 World Cup
Computers

Mexico City's Azteca Stadium is a 15-kilometer journey from the Zócalo—more or less the center of the metropolis of 18...

Read more

Norway’s wealth fund vote is latest blow to Musk’s $1 trillion pay package

by Tech Wavo
November 4, 2025
0
Elon Musk confirms shutdown of Tesla Dojo, ‘an evolutionary dead end’ 
Computers

Norway’s sovereign wealth fund has voted against a Tesla proposal to give CEO Elon Musk a compensation package worth $1...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock