XWorm Rises Again: Dissecting the Modular Malware's V6 Resurrection
ID: face34e2-f4ee-5f66-bd60-b2ca84f6ac41
STIX ID: report--face34e2-f4ee-5f66-bd60-b2ca84f6ac41
Feed Name: Resources-2
**XWorm RAT V6.0** has re-emerged as a modular, actively exploited malware family: this report documents a phishing-driven, multi-stage infection chain (JS dropper → PowerShell evasion → DLL injector → in-memory XWorm client), a wide plugin ecosystem enabling remote shell, network reconnaissance, browser credential theft, file management and ransomware, robust persistence (including ResetConfig.xml that can survive factory reset), and observed IOCs such as C2 94.159.113.64:4411 and default configuration keys; it concludes with detection and mitigation recommendations (EDR, email/web filtering, network monitoring, and persistence artifact checks).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
