We opened a fake invoice and fell down a retro XWorm-shaped wormhole
ID: ab3c2fab-763f-571c-8bf4-c14ec92d4ade
STIX ID: report--ab3c2fab-763f-571c-8bf4-c14ec92d4ade
Feed Name: Malwarebytes Blog
This analysis describes a malicious "invoice" email containing a .vbs attachment that drops a BAT and uses a PowerShell loader to decrypt, decompress and load Backdoor.XWorm directly into memory; the RAT can steal files and credentials, log keystrokes, and install further malware. The report provides a step-by-step technical breakdown of the VBS/BAT/PowerShell chain, deobfuscation methods, the extracted payload behavior (including a known mutex and SHA256), file IOCs, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
