Malicious Code Injection Detected in Windows Program by New XWorm V6 Variant
ID: 94e7e279-037e-574e-b624-905660033f1a
STIX ID: report--94e7e279-037e-574e-b624-905660033f1a
Feed Name: Cyber Press
This report documents the resurgence and active deployment of XWorm V6.0, a modular RAT distributed through phishing JavaScript droppers that chain into PowerShell and an injector DLL. XWorm uses process hollowing/injection into trusted executables (e.g., RegSvcs.exe) to evade detection, communicates with C2 at 94.159.113.64:4411, and supports >35 plugins including credential stealers, RemoteDesktop.dll, FileManager.dll, and a Ransomware.dll; it employs layered persistence (Run keys, logon scripts, InstallUtil loops, and even recovery-folder reinstall) to maintain long-term access. Analysts observed increased VirusTotal submissions indicating active adoption, and the report recommends EDR, email/web defenses, and network monitoring to detect in-memory injection, suspicious registry writes, and C2 activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
