The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the Qilin ransomware group. They exploited the NETXLOADER malware loader and SmokeLoader, causing 45 confirmed data breaches in a matter of weeks, surpassing major rivals like Akira, Play, and Lynx.
What Is NETXLOADER?
By infosecbulletin
/ Wednesday , September 17 2025
A threat actor claims to have breached Link3, a major IT solutions and internet service provider based in Bangladesh. The...
Read More
By infosecbulletin
/ Wednesday , September 17 2025
Check point, a cyber security solutions provider hosts an event titled "securing the hyperconnected world in the AI era" at...
Read More
By infosecbulletin
/ Tuesday , September 16 2025
Cross-Site Scripting (XSS) is one of the oldest and most persistent vulnerabilities in modern applications. Despite being recognized for over...
Read More
By infosecbulletin
/ Monday , September 15 2025
Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
By infosecbulletin
/ Monday , September 15 2025
A critical permission misconfiguration in the IBM QRadar Security Information and Event Management (SIEM) platform could allow local privileged users...
Read More
By infosecbulletin
/ Monday , September 15 2025
Australian banks are now using bots to combat scammers. These bots mimic potential victims to gather real-time information and drain...
Read More
By infosecbulletin
/ Saturday , September 13 2025
F5 plans to acquire CalypsoAI, which offers adaptive AI security solutions. CalypsoAI's technology will be added to F5's Application Delivery...
Read More
By infosecbulletin
/ Saturday , September 13 2025
The Villager framework, an AI-powered penetration testing tool, integrates Kali Linux tools with DeepSeek AI to automate cyber attack processes....
Read More
By infosecbulletin
/ Saturday , September 13 2025
Samsung released its monthly Android security updates, addressing a vulnerability exploited in zero-day attacks. CVE-2025-21043 (CVSS score: 8.8) is a...
Read More
By infosecbulletin
/ Saturday , September 13 2025
Albania has appointed the first AI-generated government minister to help eliminate corruption. Diella, the digital assistant meaning Sun, has been...
Read More
NETXLOADER is a new .NET-based malware loader that discreetly delivers second-stage payloads such as Agenda ransomware and SmokeLoader. Trend Micro reports that it uses .NET Reactor 6 for heavy obfuscation and incorporates advanced evasion techniques.
Just-In-Time (JIT) hooking
Control flow obfuscation
Meaningless method names
These features make NETXLOADER very difficult to find and understand, even for experienced reverse engineers.
The Qilin Ransomware Threat:
Qilin, also known as Agenda, has been active since mid-2022 and has evolved over time. Its recent success is partly due to increased affiliate support following the shutdown of RansomHub, a major ransomware group.
According to Group-IB, leak site activity related to Qilin more than doubled since February 2025:
February: 48 disclosures
March: 44 disclosures
April: 45+ disclosures in the first few weeks
Attack Vectors and Targeted Sectors
Initial access is typically achieved using:
Compromised credentials
Spear-phishing campaigns
Once inside the network, NETXLOADER downloads malware that installs Agenda ransomware using a specific method.
Targeted sectors include:
Healthcare
Financial services
Technology
Telecommunications
Countries most impacted so far are the U.S., Netherlands, Brazil, India, and the Philippines.
A Call for Vigilance:
This surge underscores the need for robust cybersecurity hygiene, including:
Regular vulnerability assessments
Endpoint detection and response (EDR) solutions
Advanced email security
User training against phishing