logo

Attack chain leads to XWORM and AGENTTESLA

ID: 04b12307-83c8-504d-9b1d-0abba6ba5bd5

STIX ID: report--04b12307-83c8-504d-9b1d-0abba6ba5bd5

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2023-04-10

Date Updated: 2026-04-27

...
...

This report describes an active malware campaign using weaponized Word/RTF documents that download obfuscated PowerShell and a custom .NET loader to memory-load XWORM and AgentTesla; the actors use AMSI bypasses, scheduled tasks, persistence under C:\ProgramData\MinMinons, process hollowing into signed .NET binaries, and a Discord webhook for exfiltration, with several hosted URLs and YARA detection rules provided as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.