logo

Multi-Stage PyInstaller Loader Weaponizes AMSI Patching to Deploy XWorm RAT

ID: c7110bb1-ff30-5fda-adf8-1800610e2c45

STIX ID: report--c7110bb1-ff30-5fda-adf8-1800610e2c45

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

Point Wild provides a technical deep-dive into a sophisticated multi-stage PyInstaller-based loader that disables AMSI via in-memory patching, reconstructs and decrypts a zlib-compressed payload using a SHA-512-derived key, and deploys the XWorm RAT (V7.4). The report details stealth techniques (randomized filenames, junk bytes to alter hashes, hidden file attributes), execution flow, and C2 communications to tcp://68.219.64.89:4444, and enumerates the RAT’s capabilities including system profiling, remote script execution, in-memory execution, and botnet/DDoS features.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.