logo

Malware stories: Deworming the XWorm

ID: 019f95be-4d96-595d-a124-0179f9b78404

STIX ID: report--019f95be-4d96-595d-a124-0179f9b78404

Feed Name: CERT Polska

Threat Score
72/100

Date Published: 2023-10-24

Date Updated: 2026-04-19

Author: Jarosław Jedynak

...
...

This report provides an in-depth technical analysis of the XWorm .NET malware family: describing multi-stage unpacking and deobfuscation, AES-based config decryption, implemented capabilities (RAT functions, keylogger, USB spreading, plugin support, DDoS and remote execution), the C2 protocol, a list of sample hashes and C2 servers, and an automated extractor to retrieve and decrypt configs for detection and threat intelligence purposes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.