logo

Cutting Through the Noise: A Technique-Based Approach to Hunting Web-Delivered Malware

ID: c65b5f70-b72a-5742-a98d-ee60618c8849

STIX ID: report--c65b5f70-b72a-5742-a98d-ee60618c8849

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2026-04-02

Date Updated: 2026-04-27

...
...

This report describes a technique-based Censys HTTP-body hunt that discovered a ClickFix social-engineering campaign hosted on orcanmedikal.com.tr which delivered a steganography-backed PhantomVAI .NET loader (embedded in a JPEG) that reverses and base64-decodes a staged payload and process-hollows to deploy XWorm V5.6; the analysis includes static recovery of the XWorm binary, extraction of its AES-encrypted configuration (C2: 86.106.85.194:9000), file hashes, IOCs, and recommended host/network detection priorities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.