Xworm RAT Posed as ScreenConnect RMM Tool to Deceive Users into Malicious Download
ID: eab807ab-b699-529f-9d7c-13c777468312
STIX ID: report--eab807ab-b699-529f-9d7c-13c777468312
Feed Name: Cyber Press
Trustwave SpiderLabs identified an active, multi-stage campaign using fake AI websites and a legitimately signed but modified ScreenConnect installer to deliver Xworm RAT; the attack chain included obfuscated Python payloads from GitHub, process hollowing and hidden desktop execution to evade detection, persistence via Windows Run keys, credential theft from browsers, and C2 communications (notably 5.181.165.102:7705), with many behaviors bypassing automated EDR and requiring human-led threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
