home.social

#xworm — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #xworm, aggregated by home.social.

fetched live
  1. The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications

    Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.

    Pulse ID: 6a7a8be76fe0dfa36d01afa0
    Pulse Link: otx.alienvault.com/pulse/6a7a8
    Pulse Author: AlienVault
    Created: 2026-08-11 02:41:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault

  2. Чемпионат по контрактам: изучаем эволюцию атак киберпреступной группировки xplogs22

    Киберпреступные группы, атакующие Россию, отличаются разнообразием. Среди них есть те, кто специализируется на взломе исключительно российских компаний, а есть и такие, для кого организации в РФ — главная, но далеко не единственная цель. И среди них есть тоже разделение: одни киберпреступники предпочитают работать преимущественно по странам СНГ, а другие масштабируют свои атаки на Западную Европу, Ближний Восток и Юго-Восточную Азию. В этом блоге разберем атаки одной из таких группировок - xplogs22 .

    habr.com/ru/companies/F6/artic

    #xplogs22 #xworm #SnakeKeylogger #formbook #фишинговые_рассылки #threat_intelligence

  3. Watch out, hackers are hiding a new version of XWorm malware in #PyInstaller files to bypass Windows security, steal data, and remotely control computers through ads!

    Read: hackread.com/hackers-pyinstall

    #CyberSecurity #XWorm #Windows #Malware #Scam

  4. New XWorm 7.1 and Remcos RAT campaigns are abusing trusted #Windows utilities and memory-based execution to evade detection, giving attackers remote access to infected systems. The campaign also exploits a #WinRAR vulnerability to gain initial access.

    Read: hackread.com/xworm-7-1-remcos-

    #CyberSecurity #Malware #XWorm #RemcosRAT

  5. 📢⚠️ Hackers are exploiting an old Excel vulnerability to spread XWorm 7.2 malware hidden in JPEG files disguised as invoices. The attack steals passwords and Wi-Fi keys and grants remote access to infected PCs.

    Read: hackread.com/hackers-excel-exp

    #CyberSecurity #Malware #Phishing #XWorm #MicrosoftExcel

  6. 2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at malware-traffic-analysis.net/2

    I've also added three other blog entries from infections I generated in my lab on Tuesday, 2026-01-20. Those can be found at malware-traffic-analysis.net/2

    Those three other entries cover #LummaStealer, #VIPRecovery, and #Xworm. The VIP Recovery and Xworm infections followed the same chain of events, which includes #steganography through base64 text embedded in an image.

  7. #xworm #asyncrat #purehvnc at:

    https:// locale-respondent-realtor-excellent.trycloudflare\.com

  8. RE: infosec.exchange/@threatinsigh

    Auch wir beobachten diese #XWorm-Welle und sehen Verbindungen zum C2-Server in den Netflows.

    Wir informieren betroffene Einrichtungen. 🤗