Netskope Threat Labs Uncovers New XWorm’s Stealthy Techniques
ID: 4fef4ee7-f72f-52a3-b28e-86cc3ba428d7
STIX ID: report--4fef4ee7-f72f-52a3-b28e-86cc3ba428d7
Feed Name: Netskope Threat Labs
Netskope Threat Labs provides a technical breakdown of XWorm v5.6, a .NET backdoor deployed via a WSF/PowerShell infection chain that uses reflective DLL loading (NewPE2) to inject XWorm into a legitimate RegSvcs.exe process, establishes a TCP socket C2 (ziadonfire.work.gd:7000), maintains persistence via a scheduled task, notifies attackers via Telegram, and exposes capabilities such as host reconnaissance, screenshot capture, hosts file modification, plugin management (including removal), and DDoS functionality, alongside IOCs and recommended detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
