logo

Malicious Code Injection Detected in Windows Program by New XWorm V6 Variant

ID: 94e7e279-037e-574e-b624-905660033f1a

STIX ID: report--94e7e279-037e-574e-b624-905660033f1a

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2025-10-03

Date Updated: 2026-04-13

Author: Priya

...
...

This report documents the resurgence and active deployment of XWorm V6.0, a modular RAT distributed through phishing JavaScript droppers that chain into PowerShell and an injector DLL. XWorm uses process hollowing/injection into trusted executables (e.g., RegSvcs.exe) to evade detection, communicates with C2 at 94.159.113.64:4411, and supports >35 plugins including credential stealers, RemoteDesktop.dll, FileManager.dll, and a Ransomware.dll; it employs layered persistence (Run keys, logon scripts, InstallUtil loops, and even recovery-folder reinstall) to maintain long-term access. Analysts observed increased VirusTotal submissions indicating active adoption, and the report recommends EDR, email/web defenses, and network monitoring to detect in-memory injection, suspicious registry writes, and C2 activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.