Excel Trap: New Phishing Campaign Deploys Fileless XWorm RAT
ID: d28ad4c6-2cdc-5f7d-bf3f-7d4d07c03500
STIX ID: report--d28ad4c6-2cdc-5f7d-bf3f-7d4d07c03500
Feed Name: securityonline.info
Threat Score
A recent phishing campaign uses business-themed lures and malicious Excel add-in (.XLAM) files exploiting CVE-2018-0802 to deliver XWorm RAT (v7.2). The multi-stage attack retrieves an HTA that runs PowerShell to load a fileless .NET payload hidden inside a JPEG, then uses process hollowing into Msbuild.exe to execute the RAT, which provides remote control, surveillance, data theft, ransomware and DDoS capabilities and communicates with AES-encrypted C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
