logo

Malware Campaign Leverages SVGs, Email Attachments, and CDNs to Drop XWorm and Remcos via BAT Scripts

ID: de66817e-0ee7-5dc9-baa9-fcabc2951043

STIX ID: report--de66817e-0ee7-5dc9-baa9-fcabc2951043

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-09-11

Date Updated: 2026-04-30

Author: Vaibhav Billade

...
...

This report documents two campaigns delivering XWorm and Remcos RATs via obfuscated BAT-based loaders and PowerShell (including SVG-based delivery), describing fileless in-memory execution, AMSI/ETW disabling, persistence via Startup, multiple loader variants (Assembly.Load and shellcode execution), IOCs (MD5s), detections, and mapped MITRE ATT&CK techniques; it emphasizes the evolving use of non-traditional file formats and obfuscation to evade static defenses and recommends behavioral detection and content inspection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.