
Beware of Weaponized MSI Installer Masquerading as WhatsApp to Deliver XWorm RAT
A newly identified cyber threat linked to a China-based threat actor has emerged, targeting users across East and Southeast Asia.
GBHackers Security | #1 Globally Trusted Cyber Security News Platform🚨 Hackers target script kiddies with a Trojanized XWorm RAT builder, compromising 18,000+ devices! Sensitive data stolen via Telegram-based C&C.
Read: https://hackread.com/hackers-script-kiddes-xworm-rat-compromise-devices/
#CyberSecurity #Malware #XWormRAT #CyberAttack

Hackers Use XWorm RAT to Exploit Script Kiddies, Pwning 18,000 Devices
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
Hackread - Latest Cybersecurity, Tech, Crypto & Hacking NewsRecent #stegocampaign delivering #XWorm RAT #malware samples.
Quick review of #sandbox analysis reports reveal simple, yet interesting infection chain. It contains #VisualBasic script, #PowerShell scripts, picture with Base64-encoded executable and the #xwormrat itself. Those payloads have been downloaded from online hosting services such as #Pastebin and #Firebase.
My new article with #IOC and analysis https://malwarelab.eu/posts/stego-xworm/
#steganography #Steganoanalysis #anyrun #malwareanalysis #obfuscation #cyberchef
XWorm RAT and Steganography :: MWLab — Ladislav's Malware Lab
When I looked on recent public submissions on Any.Run this week, my attention was attracted by XWorm samples with tags “stegocampaign”. Quick review of analysis reports reveal simple, yet interesting infection chain. It contains Visual Basic script, PowerShell script, picture with Base64-encoded executable and the XWorm RAT itself. Those payloads have been downloaded from online hosting services such as Pastebin or Firebase. Moreover, they have been downloaded via HTTPs, so basic network analysis does not reveal the content nor the URL links, however, there are some simple methods how to reveal the real URLs.
XWorm RAT and Steganography
XWorm RAT: Avira-Sicherheitsexperten warnen vor Malware
Sicherheitsexperten von Avira warnen vor der Malware XWorm RAT
heise online
XWorm RAT: Avira-Sicherheitsexperten warnen vor Malware
Sicherheitsexperten von Avira warnen vor der Malware XWorm RAT
heise online