216.73.216.233

XWorm V6: Exploring Pivotal Plugins

· Published 06/10/2025 18:58 · Modified 06/10/2025 19:17

Export JSON

Essential information

Published
06/10/2025 18:58
Modified
06/10/2025 19:17
Tags
2025-10-06 amsi bypass file manager javascript phishing powershell rat remote desktop xworm
Related entities
22 observables, 1 intrusion sets (apt), 10 techniques (mitre), 1 malware

Description

Since the release of V6.0 on June 4, 2025, we have noted a surge in samples identified as V6.0 on VirusTotal, reflecting its rapid adoption by threat actors. One prominent campaign illustrates its delivery: a malicious (JS) file initiates a (PS1) script, which deploys an injector to deliver the Client.

External references