🚨 Hackers target script kiddies with a Trojanized XWorm RAT builder, compromising 18,000+ devices! Sensitive data stolen via Telegram-based C&C.
Read: https://hackread.com/hackers-script-kiddes-xworm-rat-compromise-devices/
🚨 Hackers target script kiddies with a Trojanized XWorm RAT builder, compromising 18,000+ devices! Sensitive data stolen via Telegram-based C&C.
Read: https://hackread.com/hackers-script-kiddes-xworm-rat-compromise-devices/
Recent #stegocampaign delivering #XWorm RAT #malware samples.
Quick review of #sandbox analysis reports reveal simple, yet interesting infection chain. It contains #VisualBasic script, #PowerShell scripts, picture with Base64-encoded executable and the #xwormrat itself. Those payloads have been downloaded from online hosting services such as #Pastebin and #Firebase.
My new article with #IOC and analysis https://malwarelab.eu/posts/stego-xworm/
#steganography #Steganoanalysis #anyrun #malwareanalysis #obfuscation #cyberchef
#XWormRAT: Avira-Sicherheitsexperten warnen vor #Malware | heise online https://www.heise.de/news/XWorm-RAT-Avira-Sicherheitsexperten-warnen-vor-Malware-8976282.html
XWorm RAT: Avira-Sicherheitsexperten warnen vor Malware | heise online
https://www.heise.de/news/XWorm-RAT-Avira-Sicherheitsexperten-warnen-vor-Malware-8976282.html #Cybercrime #Malware #XWormRAT #XWorm