logo

We opened a fake invoice and fell down a retro XWorm-shaped wormhole

ID: ab3c2fab-763f-571c-8bf4-c14ec92d4ade

STIX ID: report--ab3c2fab-763f-571c-8bf4-c14ec92d4ade

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2025-11-13

Date Updated: 2026-04-28

...
...

This analysis describes a malicious "invoice" email containing a .vbs attachment that drops a BAT and uses a PowerShell loader to decrypt, decompress and load Backdoor.XWorm directly into memory; the RAT can steal files and credentials, log keystrokes, and install further malware. The report provides a step-by-step technical breakdown of the VBS/BAT/PowerShell chain, deobfuscation methods, the extracted payload behavior (including a known mutex and SHA256), file IOCs, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.