216.73.216.36

XWorm: Analyzing New Infection Tactics With Old Payload

· Published 04/12/2024 17:00 · Modified 05/12/2024 09:54

Export JSON

Essential information

Published
04/12/2024 17:00
Modified
05/12/2024 09:54
Tags
2024-12-04 keylogging lnk file multi-stage infection powershell python shellcode injection xworm
Related entities
7 techniques (mitre), 1 malware

Description

A recent malware campaign utilizes a chain starting with a that lures victims into opening an invoice in a web browser. The attack involves commands, batch files, and scripts to download and execute the payload. The infection process includes downloading a ZIP file containing setup files and scripts, with a malicious script responsible for decrypting and injecting shellcode. The variant employed is an older version that includes an Xlogger module for tracking user activities. The malware's capabilities include and , enabling the theft of sensitive information and exfiltration to a remote server.

External references