logo

Xworm RAT Posed as ScreenConnect RMM Tool to Deceive Users into Malicious Download

ID: eab807ab-b699-529f-9d7c-13c777468312

STIX ID: report--eab807ab-b699-529f-9d7c-13c777468312

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2025-08-28

Date Updated: 2026-05-05

Author: Priya

...
...

Trustwave SpiderLabs identified an active, multi-stage campaign using fake AI websites and a legitimately signed but modified ScreenConnect installer to deliver Xworm RAT; the attack chain included obfuscated Python payloads from GitHub, process hollowing and hidden desktop execution to evade detection, persistence via Windows Run keys, credential theft from browsers, and C2 communications (notably 5.181.165.102:7705), with many behaviors bypassing automated EDR and requiring human-led threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.