New XWorm 7.1 and Remcos RAT Attacks Abuse Windows Tools to Evade Detection
ID: 7fc61e88-2473-58f0-b622-a7c8db01a5b6
STIX ID: report--7fc61e88-2473-58f0-b622-a7c8db01a5b6
Feed Name: HackRead
Threat Score
Trellix research outlines two active, high-risk campaigns that use fileless RATs—XWorm (7.1/7.2) and Remcos—to achieve stealthy remote access and data theft; attackers exploit a WinRAR flaw (CVE-2025-8088) and distribute malicious archives via Discord and phishing, then abuse aspnet_compiler.exe and employ process hollowing to run solely in memory, evading traditional signature-based defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
