Multi-Stage PyInstaller Loader Weaponizes AMSI Patching to Deploy XWorm RAT
ID: c7110bb1-ff30-5fda-adf8-1800610e2c45
STIX ID: report--c7110bb1-ff30-5fda-adf8-1800610e2c45
Feed Name: securityonline.info
Point Wild provides a technical deep-dive into a sophisticated multi-stage PyInstaller-based loader that disables AMSI via in-memory patching, reconstructs and decrypts a zlib-compressed payload using a SHA-512-derived key, and deploys the XWorm RAT (V7.4). The report details stealth techniques (randomized filenames, junk bytes to alter hashes, hidden file attributes), execution flow, and C2 communications to tcp://68.219.64.89:4444, and enumerates the RAT’s capabilities including system profiling, remote script execution, in-memory execution, and botnet/DDoS features.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
