One of the Most Devious Malware Strains Might Have Been Cracked - and It's All Thanks to Gen AI

One of the Most Devious Malware Strains Might Have Been Cracked - and It's All Thanks to Gen AI

TechRadar
TechRadarNov 4, 2025

Why It Matters

The breakthrough demonstrates how generative AI can dramatically speed up malware analysis, enabling quicker detection and mitigation of sophisticated threats like XLoader. This could reshape cybersecurity operations by improving response times and reducing analyst workload across the industry.

Summary

Check Point Research used generative AI, specifically ChatGPT, to semi‑automate the reverse‑engineering of the evasive XLoader infostealer, a malware family active since 2021 and derived from Formbook. By coupling cloud‑based static analysis of IDA Pro outputs with AI‑assisted runtime debugging, the team identified encryption algorithms, generated decryption scripts, extracted encryption keys, and uncovered 64 hidden C2 domains and a new sandbox‑evasion technique called "secure‑call trampoline." The AI‑enhanced workflow accelerated a traditionally manual process, making it faster, repeatable, and easier to share across teams. Check Point emphasizes that AI augments, not replaces, human analysts in malware research.

One of the most devious malware strains might have been cracked - and it's all thanks to Gen AI

Comments

Want to join the conversation?

Loading comments...