Threats Tagged 'xworm'
View all threats tagged with 'xworm'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'xworm'
Click on any threat for detailed analysis and mitigation recommendations
Beginning in 2024, a financially motivated threat actor designated BREEZE COMET has conducted sophisticated operations targeting Brazilian financial services, retail, and eCommerce organizations. The group specializes in manipulating payment systems including Pix, STR, and Boleto to conduct fraudulent transfers worth tens of thousands of USD. Their evolved tactics leverage customized malware suites written in multiple languages including Rust, Nim, Golang, and Java, alongside compromised government websites for initial access and command and control. The threat actor demonstrates advanced capabilities by targeting banking software, payment APIs, and mTLS credentials while maintaining persistent access through multiple backdoors. Evidence indicates BREEZE COMET uses generative AI to accelerate malware development and script creation, suggesting potential expansion to other Latin American and African countries based on infrastructure replication observed in Nigeria, Paraguay, Ghana, and Venezuela. Join the discussion | AlienVault OTX General | 09/01/2026, 07:05:40 UTC Added: 09/01/2026, 08:37:15 UTC |
This report details an investigation into a malware operator using GitHub repositories to stage malicious loaders and RAT payloads. The operator's infrastructure includes multiple RAT families such as AsyncRAT, DcRat, Remcos, and XWorm, along with phishing templates targeting Colombian government institutions. The delivery infrastructure spans GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns use judicial notification and traffic violation lures with password-protected archives to target Colombian organizations. The investigation highlights how operational security failures can expose entire malware production workflows beyond individual samples. Join the discussion | AlienVault OTX General | 08/29/2026, 00:24:24 UTC Added: 08/31/2026, 09:52:14 UTC |
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers. Join the discussion | AlienVault OTX General | 08/11/2026, 02:41:43 UTC Added: 08/11/2026, 07:56:13 UTC |
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks. Join the discussion | AlienVault OTX General | 07/20/2026, 09:36:09 UTC Added: 07/20/2026, 11:11:45 UTC |
Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration. Join the discussion | AlienVault OTX General | 07/16/2026, 16:06:34 UTC Added: 07/17/2026, 00:32:32 UTC |
Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone significant architectural changes from .NET to native C++, while continuing to leverage Telegram Bot API for command and control without requiring dedicated server infrastructure. The malware is distributed as Malware-as-a-Service by developer 'ShinyEnigma' for $50-90 USD. Active exploitation campaigns are conducted by threat actor cluster 'Y2K Operators' using social engineering tactics including fraudulent utilities, hacking toolkits, software cracks, gaming lures, and trojanized cybercrime tools. The trojan enables exfiltration of sensitive browser and system data, screenshot and audio capture, keylogging, and arbitrary executable downloads. Over 62,000 compromised endpoints across more than 160 countries have been identified, with 39,730 infections occurring in Q1 2026 alone, demonstrating accelerating infection rates. Join the discussion | AlienVault OTX General | 06/25/2026, 18:43:48 UTC Added: 06/26/2026, 08:31:07 UTC |
A sophisticated phishing campaign was identified distributing multiple malware families through a multi-stage loader utilizing steganography and fileless techniques. The infection chain begins with archive attachments containing files disguised as financial documents, primarily targeting Indian organizations using names related to GST, NEFT, RTGS, and IMPS transactions. The loader employs in-memory execution to avoid disk-based artifacts and uses embedded .NET Bitmap objects to conceal payloads. Various malware families have been deployed including Remcos RAT, Agent Tesla, MassLogger, Phantom Stealer, Dark Cloud, Red Line Stealer, Snake keyloggers, Formbook, and xworm. The final payloads establish persistence through registry Run keys, perform process hollowing, steal browser credentials, record audio and webcam, and exfiltrate data to command-and-control infrastructure. The campaign exhibits characteristics of a loader-as-a-service operation serving multiple threat actors globally. Join the discussion | AlienVault OTX General | 06/23/2026, 17:35:20 UTC Added: 06/23/2026, 19:39:17 UTC |
A multi-stage malware delivery campaign was uncovered, initially detected through a suspicious VBS file. The investigation revealed a complex attack infrastructure using Unicode obfuscation, PNG-based payload staging, and reflectively loaded .NET execution. The attacker utilized open directories to host multiple obfuscated VBS files, each mapping to different malware payloads including XWorm and Remcos RAT. A secondary infection vector involving a weaponized 'PDF' and batch script was also discovered. The campaign demonstrated a modular approach, allowing for payload rotation and multiple attack vectors from the same domain. This sophisticated infrastructure design enables rapid modification and expansion of available payloads without altering the initial delivery mechanism. Join the discussion | AlienVault OTX General | 03/24/2026, 08:49:51 UTC Added: 03/24/2026, 11:31:18 UTC |
TA584, a prominent initial access broker targeting organizations globally, demonstrated significant changes in attack strategies throughout 2025. The actor expanded its global targeting, adopted ClickFix social engineering techniques, and began delivering new malware called Tsundere Bot. TA584's operational tempo increased, with monthly campaigns tripling from March to December. The actor uses various delivery methods via email, often sending from compromised individual accounts. TA584's campaigns now feature rapid succession and overlapping, with distinct lure themes and short operational lifespans. The actor has shown adaptability in social engineering, brand impersonation, and payload delivery, making static detection less effective. Recent payloads include XWorm with the 'P0WER' configuration and the newly observed Tsundere Bot, both likely part of Malware-as-a-Service offerings. Join the discussion | AlienVault OTX General | 01/28/2026, 18:26:15 UTC Added: 01/28/2026, 21:20:56 UTC |
The Brazilian Caminho loader is a sophisticated malware delivery mechanism active since March 2025, leveraging LSB steganography to hide . NET payloads within images hosted on legitimate platforms. It initiates infection via phishing emails containing malicious scripts that download these steganographic images. The loader executes payloads filelessly in memory and establishes persistence using scheduled tasks. Caminho operates as a Loader-as-a-Service, delivering multiple malware families such as Remcos RAT, Xworm, and Katz stealer across South America, Africa, and Eastern Europe. Its use of bulletproof hosting and Portuguese language artifacts indicates a Brazilian origin and professional operation. The campaign targets multiple industries opportunistically without a specific sector focus. The infection chain employs multiple advanced techniques including fileless execution, steganography, and obfuscation, complicating detection and mitigation efforts. European organizations, especially in Eastern Europe, face risks of data theft, espionage, and system compromise. Mitigation requires targeted email security, memory scanning, and monitoring of scheduled tasks for persistence. Join the discussion | AlienVault OTX General | 10/22/2025, 04:00:17 UTC Added: 10/22/2025, 12:09:03 UTC |
Showing 1 to 10 of 19 results