logo

XWorm: Analyzing New Infection Tactics With Old Payload

ID: b8acfad2-774c-53f2-b679-483f5a15cb2b

STIX ID: report--b8acfad2-774c-53f2-b679-483f5a15cb2b

Feed Name: Seqrite Blog

Threat Score
70/100

Date Published: 2024-12-04

Date Updated: 2026-04-30

Author: Rumana Siddiqui

...
...

This report details a multi-stage XWorm malware campaign that begins with a malicious LNK opening a decoy invoice and deploying a batch file which downloads and extracts a ZIP containing Python scripts; the script (man.py) decodes RC4/Base64-encoded shellcode, uses VirtualProtect and creates a suspended notepad.exe process to inject and execute the XWorm payload via APC. The XWorm binary includes a keylogger module (Xlogger) that records keystrokes and other activity to Local/Temp/log.txt for later exfiltration, and the report provides MD5 IOCs, detection names, and relevant MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.