New XWorm RAT Campaign Uses Themed Phishing Lures and CVE‑2018‑0802 Excel Exploit to Evade Detection
ID: 886bff7d-9c9a-5305-aa6d-4890590f0b91
STIX ID: report--886bff7d-9c9a-5305-aa6d-4890590f0b91
Feed Name: cybersecurityNews.com
A recent phishing campaign was observed distributing an updated XWorm RAT through malicious Excel add-ins that abuse CVE-2018-0802. Opening the .XLAM triggers a crafted OLE object and shellcode which downloads an HTA, runs obfuscated PowerShell to retrieve a hidden .NET loader (disguised as Microsoft.Win32.TaskScheduler) that reconstructs and injects XWorm into Msbuild.exe; the RAT then connects to a C2 (berlin101.com:6000) using AES-encrypted traffic. Fortinet researchers captured the chain, enumerated domains/URLs and recommended patching Equation Editor exposure, blocking XLAM/HTA execution paths, restricting mshta.exe/PowerShell/Msbuild.exe usage, and adding detections for listed IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
