#xworm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #xworm, aggregated by home.social.
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
Чемпионат по контрактам: изучаем эволюцию атак киберпреступной группировки xplogs22
Киберпреступные группы, атакующие Россию, отличаются разнообразием. Среди них есть те, кто специализируется на взломе исключительно российских компаний, а есть и такие, для кого организации в РФ — главная, но далеко не единственная цель. И среди них есть тоже разделение: одни киберпреступники предпочитают работать преимущественно по странам СНГ, а другие масштабируют свои атаки на Западную Европу, Ближний Восток и Юго-Восточную Азию. В этом блоге разберем атаки одной из таких группировок - xplogs22 .
https://habr.com/ru/companies/F6/articles/1057908/
#xplogs22 #xworm #SnakeKeylogger #formbook #фишинговые_рассылки #threat_intelligence
-
-
Watch out, hackers are hiding a new version of XWorm malware in #PyInstaller files to bypass Windows security, steal data, and remotely control computers through ads!
Read: https://hackread.com/hackers-pyinstaller-amsi-patching-xworm-rat-v7-4/
-
New XWorm 7.1 and Remcos RAT campaigns are abusing trusted #Windows utilities and memory-based execution to evade detection, giving attackers remote access to infected systems. The campaign also exploits a #WinRAR vulnerability to gain initial access.
Read: https://hackread.com/xworm-7-1-remcos-rat-windows-tools-evade-detection/
-
#reverseloader #xworm #opendir at:
http://158.94.211\.63/dealer/
-
📢⚠️ Hackers are exploiting an old Excel vulnerability to spread XWorm 7.2 malware hidden in JPEG files disguised as invoices. The attack steals passwords and Wi-Fi keys and grants remote access to infected PCs.
Read: https://hackread.com/hackers-excel-exploit-xworm-7-2-jpeg-files-hijack-pcs/
-
#xworm dropping #originlogger , and reusing #remcos c2:
https://app.any.run/tasks/9e32da84-ba55-4ac9-96f2-b7ff02d15d6b
-
2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at https://www.malware-traffic-analysis.net/2026/01/06/index.html
I've also added three other blog entries from infections I generated in my lab on Tuesday, 2026-01-20. Those can be found at https://www.malware-traffic-analysis.net/2026/index.html
Those three other entries cover #LummaStealer, #VIPRecovery, and #Xworm. The VIP Recovery and Xworm infections followed the same chain of events, which includes #steganography through base64 text embedded in an image.
-
2nd time I've seen #xworm dropping #phantomstealer so might as well share:
https://app.any.run/tasks/f2961848-ef25-48c3-b73c-2c5e137db501
-
-
Top 3 Malware Families in Q4: How to Keep Your SOC Ready https://hackread.com/top-3-malware-families-in-q4-how-to-keep-your-soc-ready/ #ThreatIntelligence #Cybersecurity #Vulnerability #LummaStealer #AgentTesla #Security #Malware #ANYRUN #XWorm #SOC
-
RE: https://infosec.exchange/@threatinsight/115408637235710538
Auch wir beobachten diese #XWorm-Welle und sehen Verbindungen zum C2-Server in den Netflows.
Wir informieren betroffene Einrichtungen. 🤗
-
New Polymorphic Malware Undetected by Security Tools https://thecyberexpress.com/polymorphic-malware-undetected-by-security/ #TheCyberExpressNews #polymorphicmalware #remoteaccesstrojan #ThreatIntelligence #screenrecordings #TheCyberExpress #FirewallDaily #Pythonmalware #cryptomining #CyberThreats #CyberNews #keylogger #malware #XWorm
-
XWorm 6.0 Returns with 35+ Plugins and Enhanced Data Theft Capabilities
https://thehackernews.com/2025/10/xworm-60-returns-with-35-plugins-and.html #Cybercrime #Malware #XWorm #Plugins -
XWorm RAT Delivered via Shellcode: Multi-Stage Attack Analysis
#XWorm
https://www.forcepoint.com/blog/x-labs/xworm-rat-shellcode-multi-stage-analysis -
XWorm is back and more dangerous than ever—a modular malware toolbox with over 35 plug‐ins, now including ransomware. Cybercriminals have a Swiss Army knife for chaos. How prepared are you?
#xworm
#malware
#ransomware
#cyberthreats
#infosec
#modularmalware
#cybersecurity
#threatintel
#phishing -
New XWorm V6 Variant Embeds Malicious Code into Trusted Windows Applications https://gbhackers.com/xworm-v6-variant/ #CyberSecurityNews #cybersecurity #Windows #XWorm