logo

New XWorm 7.1 and Remcos RAT Attacks Abuse Windows Tools to Evade Detection

ID: 7fc61e88-2473-58f0-b622-a7c8db01a5b6

STIX ID: report--7fc61e88-2473-58f0-b622-a7c8db01a5b6

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Trellix research outlines two active, high-risk campaigns that use fileless RATs—XWorm (7.1/7.2) and Remcos—to achieve stealthy remote access and data theft; attackers exploit a WinRAR flaw (CVE-2025-8088) and distribute malicious archives via Discord and phishing, then abuse aspnet_compiler.exe and employ process hollowing to run solely in memory, evading traditional signature-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.