logo

LATAM Businesses Hit by XWorm via Fake Financial Receipts: Full Campaign Analysis 

ID: 0c704791-9926-58f6-b77f-eeab475f2363

STIX ID: report--0c704791-9926-58f6-b77f-eeab475f2363

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
70/100

Date Published: 2026-02-17

Date Updated: 2026-04-26

Author: Moises Cerqueira (0xOlympus)

...
...

This report dissects a LATAM-focused multi-stage XWorm campaign that uses a fake bank receipt lure (obfuscated WSH/JavaScript) to spawn a hidden WMI-based PowerShell loader which downloads a steganographic .jpg from Cloudinary containing an in-memory .NET persistence DLL; that DLL registers a scheduled task via .NET APIs and the final XWorm payload is injected into CasPol.exe. The analysis includes static and dynamic confirmation, decrypted configuration (C2 jholycf100.ddns.com.br / 152.249.17.145), file hashes, payload URLs, and YARA rules to aid detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.