New XWorm RAT Campaign Leverages Phishing and CVE-2018-0802 Excel Exploit to Bypass Detection
ID: 1aec7c6c-0cfa-5b32-95ca-b27ecab929db
STIX ID: report--1aec7c6c-0cfa-5b32-95ca-b27ecab929db
Feed Name: GBHackers
XWorm is an actively traded .NET Remote Access Trojan distributed via themed phishing emails delivering malicious Excel .XLAM attachments that exploit CVE-2018-0802. The multi-stage chain uses an OLE-based Office exploit to run shellcode which downloads an HTA that executes obfuscated PowerShell to load a fileless .NET module; the loader performs process hollowing into Msbuild.exe and establishes AES-encrypted C2 with a modular plugin system enabling data theft, remote control, DDoS, and ransomware. Defenders are advised to apply Office patches, restrict OLE/HTA/PowerShell execution, and monitor anomalous Office→mshta/PowerShell→Msbuild process chains and suspicious outbound encrypted traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
