XORIndex Loader
S1248 · Windows
XORIndex Loader is a XOR-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail malware. XORIndex Loader was first reported in June 2025. XORIndex Loader has been leveraged by North Korea-affiliated threat actors identified as Contagious Interview.
XORIndex Loader has been delivered to victims through code repository sites utilizing typo squatting naming conventions of various npm packages.
ATT&CK S1248
Sigma rules0
YARA rules0
Live IOCs0