Attack chain leads to XWORM and AGENTTESLA
ID: 04b12307-83c8-504d-9b1d-0abba6ba5bd5
STIX ID: report--04b12307-83c8-504d-9b1d-0abba6ba5bd5
Feed Name: Elastic Security Labs
Threat Score
This report describes an active malware campaign using weaponized Word/RTF documents that download obfuscated PowerShell and a custom .NET loader to memory-load XWORM and AgentTesla; the actors use AMSI bypasses, scheduled tasks, persistence under C:\ProgramData\MinMinons, process hollowing into signed .NET binaries, and a Discord webhook for exfiltration, with several hosted URLs and YARA detection rules provided as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
