Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

XRed

52
Global rank
65 infographic chevron month
Month rank
56 infographic chevron week
Week rank
0
IOCs

XRed operates as a stealthy backdoor, enabling cybercriminals to gain unauthorized remote access to infected systems. XRed has gained particular notoriety for its distribution through trojanized legitimate software and hardware drivers, making it exceptionally dangerous due to its ability to masquerade as trusted applications.

Backdoor
Type
Unknown
Origin
1 April, 2019
First seen
24 August, 2026
Last seen

How to analyze XRed with ANY.RUN

Type
Unknown
Origin
1 April, 2019
First seen
24 August, 2026
Last seen

IOCs

IP addresses
163.171.131.248
171.13.14.66
42.236.9.26
172.217.115.4
121.4.25.139
171.8.167.89
184.86.251.15
2.16.241.201
104.192.108.133
180.153.232.138
36.99.172.103
116.163.31.134
157.185.128.14
49.234.241.8
40.126.32.136
104.192.108.20
48.209.138.168
116.153.4.140
103.28.8.52
1.192.137.3
Hashes
df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
e150816e78d55c136b4ab0e1c406f22f4102e59d032c5a014e74a6a60bb09b08
32d83ff113fef532a9f97e0d2831f8656628ab1c99e9060f0332b1532839afd9
c0ec75b44dbecb80d621d4600d124544536efb0a5e40b4cd927f9f8145c61f94
72d936e41f4c9ae8c66e5bf8e58a6b6653651372acd3f198fc9a28fc7325beec
c0c661230b1bd30f5f76e2a68bb0120f27fb274779953a5393e22bb5a1dcc624
5d297c94d94529bb652405c76bfdd7b2d8365cc6cddc72310ab250242ea12145
bb393ebae1fd656b019cd086c05fcece979405c4616989bfdde6d60044d08b8d
273ce954c8d33abaac3a0fd8546719f09718c1d91317ecf5b99181dffa3fe26a
75e3b13c119bd4025f3fbf97b29f31d8e215a8d177ef854994a8ba2cbbac4f44
b4348c968e41541a849fd7ec54a059330157598fc34437c4356875ba76fa4a5d
4e8351e52cf2493492a66f1b66799b2a65aa8ce27d6275a73773091cbf8a9be5
523a2018584433b185eff9d8039b90ee14693f1ce0e1658854055a06a31e0bbd
657ea97f0c25b1146bc4bcb1b6e22bab67d7128a2e9aa710d81673b2564785cb
d4551ea4ec7002cfd44235a9f27fe3c7f99e8d45cdc112bfd26ac55c61ec24bb
43290158d2157db03c653bd922e05d0ab8b8e29fd18b33143aca6cfe5e299069
823c745604787e88bb7fb63260b852afdc2e148381bacc29237bb2a26b5f8f6f
f47e685eb7528817dac19be0692761bbaef8e3c734a6638f846be80134f1e7b4
a5f6f150c066554a3f99584f57069b9d336f58405d014a262923793f09740bac
1ad9ba987664ea8f183ed790171e640f1bf4289a5067221c24db1718581b8e03
Domains
p3.ssl.qhimg.com
u.qurl.f.360.cn
p5.ssl.qhimg.com
qurl.f.360.cn
bp.conf.f.360.cn
s.bbm0v.cn
sconf.f.360.cn
tconf.f.360.cn
pinst.360.cn
client.wns.windows.com
update.googleapis.com
qup.f.360.cn
tconf2.f.360.cn
clientservices.googleapis.com
edge.microsoft.com
p2.ssl.qhimg.com
fe3cr.delivery.mp.microsoft.com
down.wukongsafe.cn
agd.p.360.cn
login.live.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
http://clients2.google.com/time/1/current?cup2key=8:jdfbbw49drna4ff35vnvpjqj7m9-3ej5ug3bkjpacly&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
http://down.wukongsafe.cn/msbp/wukonginstallerbypass+8000006.exe
https://update.googleapis.com/service/update2/json?cup2key=14:0advjhag9mbjof-gvdogvmdc6v9r52dogzrnn0lyjyc&cup2hreq=b8af6c2d65784fe4bc719de3ee394937a58d8667569cc5a1f1d79ff845f78dfe
https://sb-ssl.google.com/safebrowsing/clientreport/download?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://optimizationguide-pa.googleapis.com/v1:getmodels?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://optimizationguide-pa.googleapis.com/downloads?name=1679317318&target=optimization_target_language_detection
https://optimizationguide-pa.googleapis.com/downloads?name=1753110098&target=optimization_target_notification_permission_predictions
https://optimizationguide-pa.googleapis.com/downloads?name=1781017313&target=optimization_target_client_side_phishing
https://optimizationguide-pa.googleapis.com/downloads?name=1753110074&target=optimization_target_geolocation_permission_predictions
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbsrxerf0efeswrriptgtkcjwmm7iqquadfg67y7%2bf8rhvv%2byxsiigx0tkiceaojb8tyrme0lcexrulyuya%3d
https://optimizationguide-pa.googleapis.com/downloads?name=1728324084&target=optimization_target_omnibox_on_device_tail_suggest
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://optimizationguide-pa.googleapis.com/downloads?name=1673999601&target=optimization_target_page_visibility
http://ocsp.usertrust.com/mfiwudbomewwsjajbgurdgmcgguabbtnmnjmndqcqx8fcbwk16ehdims6qquu3m%2fwqorss9ugohym8cd8ridzssceqdsf7vb3jweuhatyulyyjne
Last Seen at

Recent blog posts

post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 1206
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 7344
comments 0
post image
Hunt Malware & Phishing Threats with ANY....
watchers 7035
comments 0

What is XRed Malware?

XRed, also known as Synaptics worm, is a sophisticated backdoor malware that has emerged as a significant cybersecurity threat since at least 2019. It is designed for long-term system infiltration and control and stealing sensitive data. It combines elements of remote access Trojans (RATs), infostealers, and backdoors to execute a range of malicious activities.

The malware demonstrates advanced capabilities including self-replication, persistence mechanisms, and remote command execution. What makes XRed particularly concerning is its professional development quality.

The malware operates through a multi-stage infection process, beginning with initial compromise through trojanized software and progressing to establish persistent access for data exfiltration and system control. XRed employs various anti-detection techniques and creates multiple infection vectors to ensure continued access to compromised systems. The backdoor’s architecture allows for modular payload delivery, enabling threat actors to customize attacks based on specific targets and objectives.

XRed is often associated with cybercriminal groups and, in some cases, state-sponsored actors, who use it to target high-value assets for financial gain, espionage, or disruption.

The malware’s ability to remain undetected stems from its use of legitimate system tools (living-off-the-land techniques) and its capacity to mimic benign software processes. XRed’s development is believed to be part of the growing Cybercrime-as-a-Service (CaaS) ecosystem, where malware kits are sold on the dark web, enabling even low-skill attackers to deploy it effectively.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

XRed Victimology

XRed targets a broad spectrum of victims, with particular focus on:

Individual Users:

  • Consumers downloading software for peripheral devices (USB-C hubs, gaming mice, printers)
  • Users seeking legitimate software from compromised distribution channels
  • Technology enthusiasts and reviewers who frequently test new hardware and software

Business Sectors:

  • Small to medium enterprises with limited cybersecurity infrastructure
  • Organizations in the manufacturing and technology sectors
  • Companies that rely heavily on peripheral devices and third-party software
  • Gaming and entertainment industry stakeholders

Geographically, attacks have been reported predominantly in North America, Europe, and the Asia-Pacific region, with a notable spike in the APAC region in 2024. Individuals with access to high-value credentials, such as IT administrators or executives, are prime targets for XRed’s credential-harvesting capabilities, often through spear-phishing campaigns.

XRed Malware Typical Attack Chain

ANY.RUN’s Interactive Sandbox contains an assortment of XRed analysis sessions featuring different associated malware and attack vectors. By detonating XRed samples, we can understand the key points of its attack chain.

View analysis

XRed analysis in Sandbox XRed sample analysis in the Interactive Sandbox

XRed is delivered through trojanized programs that pose as legitimate software. When activated, the malicious file usually launches the legitimate utility it's disguised as to avoid detection.

To prevent multiple instances from running, XRed checks for the Synaptics2X mutex, which remains unchanged in the samples, and masquerades as Synaptics.exe. These are typical IOCs for XRed, and they are preserved in most instances. After creating Synaptics.exe, the file is added to the system's startup.

XRed adds file in autorun XRed adds file in autorun

Once initialized, XRed gathers system data. The backdoor also provides remote system control, supporting commands for taking screenshots, accessing the command line, managing files, and listing drives and directories.

XRed also infects Excel files by embedding a VBA script that includes malicious code, as seen in the example of file interaction.

XRed file modifications XRed file modifications filtered by extension

The embedded VBA can be viewed using the sandbox functionality.

VBA file modified by XRed VBA file modified by XRed

Exploring the sandbox analyses, we can observe the key features of XRed:

  • Masking and Stealth: XRed disguises itself as Synaptics.exe, using the legitimate name and description "Synaptics Pointing Device Driver." The payload is placed in the folder C:\ProgramData\Synaptics.
  • Information Gathering: It collects data such as the MAC address, username, and computer name, which it then sends to the attacker's server.
  • Keylogging: It uses keyboard hooks to record keystrokes.
  • Remote Commands: XRed supports commands that allow for command-line access, taking screenshots, listing drives and directories, and downloading and deleting files.
  • USB Propagation: It has an archaic feature that allows it to spread via USB drives by creating an autorun.inf file to automatically launch a copy of itself on vulnerable devices.
  • Macro Manipulation: It injects a VBA script into Excel files that disables macro security warnings and copies the malicious file to directories with legitimate files.

How Does XRed Malware Function?

XRed operates leverages several sophisticated mechanisms:

Primary Distribution Vectors:

  • Trojanized hardware drivers bundled with legitimate peripheral devices
  • Compromised software distribution websites and official download channels
  • Infected gaming peripheral configuration software
  • Malicious printer and scanner drivers distributed by manufacturers

Persistence Mechanisms:

  • Creates Windows Registry Run keys to ensure automatic startup
  • Utilizes mutex named "Synaptics2X" to prevent multiple instances
  • Implements self-replication capabilities for infection spread

Data Exfiltration:

  • Monitors clipboard activity for sensitive information
  • Captures keystrokes and system information
  • Transmits collected data to attacker-controlled servers

Evasion Techniques:

  • Use of legitimate digital certificates to bypass security controls
  • Distribution through trusted vendor channels to avoid suspicion
  • Timing-based installation to avoid real-time security scanning
  • Polymorphic code variations to evade signature-based detection

Modular Architecture:

  • Supports dynamic loading of additional malicious modules
  • Enables customization of attack capabilities based on target environment
  • Facilitates ongoing campaign adaptation and evolution

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Most Notorious XRed Attacks

While specific XRed attacks are not well-documented in public sources due to its recent emergence, several high-profile incidents in 2024 align with its TTPs:

  1. USB-C Hub Campaign (2019-2024): A long-running campaign distributing XRed through USB-C hub adapter drivers affected thousands of users across multiple years. This attack showcased the malware's persistence and the effectiveness of hardware-based distribution methods.
  2. Manufacturing Sector Breach (2024): A major manufacturing firm in the Asia-Pacific region suffered a supply chain attack where XRed was embedded in a software update, leading to the theft of intellectual property and operational disruption.
  3. Financial Institution Data Theft (2024): XRed’s infostealer capabilities compromised a U.S.-based bank, exfiltrating customer credentials and causing significant reputational damage.
  4. Healthcare Ransomware Attack (2024): A hospital network was paralyzed by XRed’s ransomware module, locking critical systems and delaying patient care, with attackers demanding a multimillion-dollar ransom.
  5. Procolored Printer Manufacturer Incident (2024-2025): This six-month-long campaign represents one of the most successful XRed distributions, where a legitimate printer manufacturer unknowingly distributed infected drivers. The attack was discovered only when YouTube technology reviewer Cameron Coward attempted to review a $6,000 printer, highlighting how the malware successfully evaded detection for an extended period.
  6. Gaming Peripheral Supply Chain Attack (2025): Endgame Gear's OP1w 4K V2 mouse configuration software was compromised for nearly two weeks, affecting numerous gaming enthusiasts and professional esports players. This attack demonstrated XRed's ability to infiltrate trusted software distribution channels and target specific user communities.
  7. Multi-Vendor Hardware Driver Campaign (2025): Coordinated attacks targeting multiple peripheral device manufacturers simultaneously, creating a broad infection surface across different vendor ecosystems. This campaign demonstrated sophisticated supply chain infiltration capabilities.

Gathering Threat Intelligence on XRed Malware

By integrating threat intelligence into security operations, organizations can stay ahead of XRed’s evolving threat landscape. It provides indicators of compromise (e.g., malicious IPs, domains, or file hashes) to block XRed’s C&C communications and offers insights into XRed’s tactics, techniques, and procedures, enabling tailored defense strategies.

It also fuels proactive threat hunting allowing organizations to search for XRed’s presence before it causes damage, using tools like YARA rules or SIEM integrations.

Start gathering IOCs and behavioral data with the malware name search request to Threat Intelligence Lookup:

threatName:"XRed"

XRed malware samples found via TI Lookup XRed malware samples found via TI Lookup

You can also search TI Lookup for the above-mentioned mutex engaged in most of the malware versions being a reliable IOC:

syncObjectName:"Synaptics2X" AND imagePath:"ProgramData\Synaptics\Synaptics.exe"

Malware samples featuring Synaptics mutex XRed malware samples featuring Synaptics mutex

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

XRed is a sophisticated and adaptable threat that demands constant vigilance. Its modular design, stealthy operation, and high-impact potential make it one of the more dangerous malware families targeting modern enterprises. Robust detection mechanisms, proactive threat intelligence, and a security-first culture are critical in defending against it.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

Bluesky Ransomware screenshot
BlueSky ransomware, first identified in June 2022, shares code similarities with other well-known ransomware families like Conti and Babuk. It primarily spreads via phishing emails and malicious links and can propagate through networks using SMB protocols. BlueSky uses advanced evasion techniques, such as hiding its processes from debuggers via the NtSetInformationThread API, making it difficult for analysts to detect and mitigate its attacks.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
ACR Stealer screenshot
ACR Stealer is a modern information-stealing malware designed to harvest sensitive data from infected devices. Like other infostealers, it targets credentials, financial details, browser data, and files, enabling cybercriminals to monetize stolen information through direct fraud or underground market sales.
Read More
ClickFix screenshot
ClickFix is a sophisticated social engineering technique that tricks users into manually executing malicious commands on their devices. It masquerades as a "quick fix" for fake technical issues, CAPTCHA verifications, or error messages, often hijacking the clipboard to paste harmful PowerShell or terminal commands. This user-assisted approach helps it bypass traditional security controls, leading to infostealers like Lumma Stealer, RATs, and other malware.
Read More
Keylogger screenshot
Keylogger
keylogger
A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More