LATAM Businesses Hit by XWorm via Fake Financial Receipts: Full Campaign Analysis
ID: 0c704791-9926-58f6-b77f-eeab475f2363
STIX ID: report--0c704791-9926-58f6-b77f-eeab475f2363
Feed Name: ANY.RUN's Cybersecurity Blog
This report dissects a LATAM-focused multi-stage XWorm campaign that uses a fake bank receipt lure (obfuscated WSH/JavaScript) to spawn a hidden WMI-based PowerShell loader which downloads a steganographic .jpg from Cloudinary containing an in-memory .NET persistence DLL; that DLL registers a scheduled task via .NET APIs and the final XWorm payload is injected into CasPol.exe. The analysis includes static and dynamic confirmation, decrypted configuration (C2 jholycf100.ddns.com.br / 152.249.17.145), file hashes, payload URLs, and YARA rules to aid detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
