Recommended Free Tools
XE Group’s reported use of two previously undocumented VeraCore vulnerabilities marks an expansion in the activity researchers observed—not proof that the group has abandoned credit-card skimming. In a joint investigation published February 3, 2025, Intezer and Solis Security linked the group’s historical web theft operations to attacks on VeraCore fulfillment software, including exploitation, credential reuse, webshell access, and attempted malware execution.
What changed in XE Group’s observed activity?
Intezer and Solis Security describe XE Group as active since at least 2013, with a history of exploiting web vulnerabilities, stealing payment-card data through skimmers, and stealing passwords. Their 2024 findings show activity focused on information theft and supply-chain software, specifically VeraCore, which the researchers say is used by fulfillment companies, commercial printers, and e-retailers.
This is evidence of an expanded or shifted operation in the incidents researchers examined. It does not establish that XE Group permanently stopped skimming or that every part of its activity changed. Intezer’s report summarizes the findings this way: “These recent discoveries highlight that XE Group is not only active but evolving.” The statement appears in the article by Nicole Fishbein, Joakim Kennedy, and Justin Lentz, published February 3, 2025, in collaboration with Solis Security. Intezer’s investigation
The phrase “zero-day” refers to the researchers’ characterization of the VeraCore flaws as previously undocumented when exploited. CVE identifiers were subsequently assigned and published; the term does not mean the vulnerabilities are still unknown or unpatched today.
#1 Best Overall
- STYLISHLY SMALL, SLIM & DISCREET: Measuring just 3 1/8" x 4 7/16", our RFID front pocket wallet is designed to be super thin and exceptionally slim. Its modern, minimalist profile fits perfectly in your pocket, purse, or travel pack without adding bulk.
- SURPRISINGLY SPACIOUS: Though slim, it features 8 slots to easily organize your essentials. Comfortably holds your driver's license, credit cards, debit cards, and membership cards, keeping everything you need right at your fingertips.
- ADVANCED RFID BLOCKING: Our slim wallets for men and women are outfitted with advanced RFID SECURE Technology. They block electronic signals to keep your identity protected while you travel, shop, or explore, safeguarding you from digital theft.
- DURABLE & STYLISH FAUX LEATHER: Crafted from premium synthetic leather, this minimalist wallet sleeve combines a luxurious look and feel with everyday functionality. Its durable construction is designed to withstand the rigors of daily use, travel, and shopping.
- THE PERFECT UNISEX GIFT: With its sleek design and practical security features, this wallet is a popular choice for both men and women. It arrives ready for gifting, making it an ideal present for the frequent traveler, minimalist, or anyone in your life!
Which VeraCore vulnerabilities did researchers identify?
The investigation identifies two distinct weaknesses. Intezer reported severity figures of 9.9 for CVE-2024-57968 and 5.8 for CVE-2025-25181 in 2025; these are Intezer’s reported scores, not independently revalidated current scores.
| Identifier | Type and described mechanism | Authentication context | Severity reported by Intezer (2025) |
|---|---|---|---|
| CVE-2024-57968 | Upload-validation flaw. Intezer says the application checked uploaded file size, and a file could be accessible through the web server if the upload feature was configured improperly. | The upload endpoint required prior authentication, according to Intezer. | 9.9 |
| CVE-2025-25181 | SQL injection in VeraCore’s timeoutWarning endpoint. Intezer says a value from the PmSess1 field was incorporated into a raw SQL query. |
Not stated in Intezer’s description. | 5.8 |
These flaws are VeraCore issues, not the Telerik UI for ASP.NET vulnerabilities associated with earlier XE Group reporting. SecurityWeek’s February 3, 2025 report also covered the findings and was updated later that day to add the CVE identifiers.
Rank #2
- Ultra-thin: This wallet measures 4.3 x 3 x 0.5 inches and can hold at least 11 cards and 15-20 bills. Even when it's packed full, it's only 0.8 inches thick,It can perfectly conceal itself in your pocket without any noticeable bulge.
- Rfid Blocking: Our wallets are equipped with German Instiute Certified RFID Security technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals to protect the valuable information and privac.
- Lifetime After-sales Service: Regardless of the circumstances, if any GSOIAX brand wallet has a quality issue during your use, we promise to provide a full, unconditional, refund within 24 hours!
- Durable Surface: Crafted from premium 3-layer leather, our wallets outperform 2-layer alternatives in durability. Specially treated leather exterior delivers enhanced scratch resistance to guard against minor scuffs from everyday items like keys and buttons.
- Perfect Gifts For Him: This Money Clips Wallets for men comes in classy gift box package. It's a good idea to send the mens wallets as the gifts in birthday,anniversaries, Fathers Day,Valentine's Day,Christmas and other special occasions to someone you love.
What did attackers do after gaining access?
Intezer’s retrospective account connects activity against the same organization across several years:
- January 2020: Attackers exploited SQL injection to retrieve credentials and uploaded webshells, according to the investigation.
- 2023: The report says the group accessed a webshell and collected application configuration files.
- November 5–6, 2024: Researchers observed renewed activity on the same system, including configuration-file collection, credential reuse, and webshell activity. The report describes more than four years between the initial compromise and renewed access.
For activity identified on November 5, 2024, researchers also saw attempts to access remote systems and obfuscated PowerShell intended to run a remote-access payload. Intezer reports that endpoint detection and response detected and prevented much of this activity. The report therefore documents attempted post-exploitation and detection, not successful execution of every attempted action.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #3
- RFID Blocking Technology: This credit card holder is made of aluminum shells and ABS plastic, designed with RFID-blocking technology to help protect your credit, ID, debit, and driver's license cards from unauthorized scanning
- Slim Compact: Slim and compact design measures 4.3 x 3 x 0.86 inches, ideal for front pockets or purses
- Card Organizer: With 7 accordion-style slots, this wallet can hold up to 10 standard credit cards or over 20 business cards
- Artistic Expression: Features a variety of artistic designs on the aluminum shell, inspired by famous paintings, flowers, and animals, to complement your personal style
- Thoughtful Gift Idea: Makes a thoughtful gift for any occasion, combining functionality and style
How did the 2020 compromise connect to activity in 2024?
The connection was persistent access to the same organization: credentials obtained during the 2020 compromise and a previously installed webshell were later reused, according to Intezer. This illustrates why an organization may need to investigate beyond the initial vulnerability or malware event. Finding and closing one entry point does not, by itself, establish that previously stolen credentials or an existing webshell have been removed.
For defenders investigating a similar incident, the reported sequence makes these areas relevant to review:
Rank #4
- SECURE YOUR WALLET FROM e-PICKPOCKETING: Prevent potential identity and financial theft through your contactless cards. This is the simplest and most effective prevention solution! Block RFID and NFC signals, protect your personal information, and enjoy peace of mind wherever your travels or business take you.
- JAMMING CHIP: An antenna and jamming chip makes up the main components of the card. The antenna will sense incoming radio waves and draw power for the chip to create a jamming signal. Lifetime usage as the card does not require battery.
- BROAD WORKING DISTANCE: With a 2.4” working distance, your entire wallet stays protected. The premium RFID blocking card helps secure cards within 1.2” on either side, providing reliable protection against electronic pickpocketing.
- ULTRA-THIN & COMPACT: At the size of a standard credit card and at only 0.03” thick, the card will fit into any wallet, purse or card case. Keep your wallet compact with no added bulk from this card. Best for travel, business, and everyday use.
- TEST THE CARD: Test the card is working at your local supermarket. At the self-service checkout machines, combine the card and a contactless card on the payment reader. Payment with the contactless card will be blocked and an error message should occur on the reader.
- Whether affected VeraCore endpoints were exposed and whether they were accessed unexpectedly.
- Whether webshells or unauthorized changes remain on application servers.
- Whether credentials used or stored in the affected environment were exposed, reused, or need rotation.
- Whether application configuration files were accessed and whether systems reachable from the server show related activity.
- Whether endpoint detection alerts recorded blocked or prevented payload activity, rather than treating an alert alone as proof of successful compromise.
What is known about fixes and current patch status?
Intezer’s technical report says the vendor issued a temporary fix for the upload flaw by removing the upload feature. That describes the response reported in the February 2025 investigation; it does not establish the present availability of a permanent fix or the current status of CVE-2024-57968.
February 2025 reporting said CVE-2025-25181 remained unpatched at that time. That is a historical status, not confirmation of its status in 2026. The available vendor release-notes information does not establish current remediation. VeraCore operators should check with the vendor for current affected versions, supported fixes, and deployment guidance rather than infer present exposure from a 2025 report.
Best Value
- Special Design: Multi-color optional and wear-proof classic business card holder looking.
- Plenty of Space: 16 card slots only measuring 4.1" x 3.0" x 1.1", including 13 credit card slots, 2 cash slots
- Protect Information Leakage: Prevents your vital information/cards from unnoticed scan with 2 outer layers RFID blocking materials.
- Extra Key Chain & Portable: Extra corns with key chain for your keys or lanyard. Portable use for shopping, traveling, etc.
- Great Gift: Practical compact wallet is the perfect gift. Give a thoughtful surprise to Men/Women on birthdays, holidays, celebrations, or any special occasion (e.g. Valentine's Day, Christmas, etc.).
CyberScoop described XE Group as believed to have Vietnamese origins while noting attribution challenges. That is a cautious assessment, not established proof of nationality or state affiliation. CyberScoop’s coverage
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

