ATT&CKSoftwareXORIndex Loader

XORIndex Loader

S1248

Malware.View on attack.mitre.org

About this malware

XORIndex Loader is a XOR-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail malware. XORIndex Loader was first reported in June 2025. XORIndex Loader has been leveraged by North Korea-affiliated threat actors identified as Contagious Interview. XORIndex Loader has been delivered to victims through code repository sites utilizing typo squatting naming conventions of various npm packages.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1016
System Network Configuration Discovery

XORIndex Loader has leveraged webservices to identify the public IP of the victim host.

T1027.010
Command Obfuscation

XORIndex Loader has obfuscated strings using ASCII buffers and TextDecoder.

T1027.013
Encrypted/Encoded File

XORIndex Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis.

T1033
System Owner/User Discovery

XORIndex Loader has collected the username from the victim host.

T1036.005
Match Legitimate Resource Name or Location

XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads.

T1041
Exfiltration Over C2 Channel

XORIndex Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers.

T1059.007
JavaScript

XORIndex Loader has executed malicious JavaScript code.

T1071.001
Web Protocols

XORIndex Loader has used HTTPS POST to communicate with C2.

T1082
System Information Discovery

XORIndex Loader has the ability to collect the hostname, OS Username, Geolocation, and OS version of an infected host.

T1105
Ingress Tool Transfer

XORIndex Loader has been used to download a malicious payload to include BeaverTail.

T1140
Deobfuscate/Decode Files or Information

XORIndex Loader can decode its payload prior to execution.

T1614
System Location Discovery

XORIndex Loader can identify the geographical location of a victim host.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Socket BeaverTail XORIndex HexEval Contagious Interview July 2025 Open source
    Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.