logo

Netskope Threat Labs Uncovers New XWorm’s Stealthy Techniques

ID: 4fef4ee7-f72f-52a3-b28e-86cc3ba428d7

STIX ID: report--4fef4ee7-f72f-52a3-b28e-86cc3ba428d7

Feed Name: Netskope Threat Labs

Threat Score
70/100

Date Published: 2024-09-30

Date Updated: 2026-04-28

Author: Jan Michael Alcantara

...
...

Netskope Threat Labs provides a technical breakdown of XWorm v5.6, a .NET backdoor deployed via a WSF/PowerShell infection chain that uses reflective DLL loading (NewPE2) to inject XWorm into a legitimate RegSvcs.exe process, establishes a TCP socket C2 (ziadonfire.work.gd:7000), maintains persistence via a scheduled task, notifies attackers via Telegram, and exposes capabilities such as host reconnaissance, screenshot capture, hosts file modification, plugin management (including removal), and DDoS functionality, alongside IOCs and recommended detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.