216.73.216.36

JScript to PowerShell: Breaking Down a Loader Delivering XWorm and Rhadamanthys

· Published 16/04/2025 05:57 · Modified 16/04/2025 13:21

Export JSON

Essential information

Published
16/04/2025 05:57
Modified
16/04/2025 13:21
Tags
2025-04-16 jscript rhadamanthys xworm
Related entities
4 observables, 11 techniques (mitre), 2 malware, 1 others

Description

This analysis examines a sophisticated malware loader that utilizes to launch obfuscated PowerShell code, ultimately delivering payloads such as and . The loader employs geofencing tactics, targeting victims in the United States with RAT, while deploying stealer to users outside the U.S. The attack chain involves multiple stages of obfuscation and deobfuscation, including decimal encoding and string manipulation. The final payload is injected into RegSvcs.exe using reflective loading techniques. The loader also performs various cleanup actions to evade detection and remove traces of its activity. Both and are advanced malware variants with capabilities ranging from DDoS attacks to cryptocurrency theft.

External references