HomeSecurityVariant of XWorm Delivered via Windows Script File

Variant of XWorm Delivered via Windows Script File

NetSkope researchers have recently identified a new variant of XWorm that is delivered via a Windows Script File. XWorm refers to a type of malware that has been analyzed for its obfuscation techniques and potential impact on systems .

See also: New CMoon worm targets Russians in data theft attacks

XWorm

This malware is known for its ability to disguise itself and evade detection, which makes it a significant cybersecurity threat.

⁤XWorm is a versatile malware tool discovered in “2022” and has since evolved to version 5.6 as recently discovered by “ Netskope Threat Labs ”. This “ .NET-based ” threat starts its infection chain via a “ Windows Script File” (“WSF”) , which downloads and executes an obscure “ PowerShell ” script from “ paste[.]ee ”. ⁤⁤

The script creates multiple files (“VsLabs.vbs”, “VsEnhance.bat” and “VsLabsData.ps1”) in “C:\ProgramData\Music\Visuals” and establishes persistence via a scheduled task called “MicroSoftVisualsUpdater”. ⁤In addition, ⁤XWorm uses evasion techniques such as “reflective loading of a DLL loader code” (“NewPE2”) and “process injection into legitimate processes” such as “RegSvcs.exe.” ⁤

XWorm communicates with the “command and control server (“C2”) via “TCP sockets”, using “ AES-ECB encryption ” with a modified “ MD5 hash ” as the key. Here new features in version 5.6 include the ability to remove add-ons and a “ Pong ” command for reporting response time.

The malware performs extensive system reconnaissance by collecting data about “hardware”, “software” and “user privileges”. Not only that, it also notifies the attackers via “Telegram” in case of “successful infection”.

See also: Gh0st RAT Trojan: Targets Chinese Windows Users via Fake Chrome Site

These sophisticated techniques allow “XWorm” to access sensitive information, gain remote access, and deploy additional malware while avoiding detection.

Windows Script File

XWorm uses multiple attack vectors and can modify host files on infected systems to redirect DNS requests for malicious purposes.

The malware launches “DDoS” attacks by sending repeated “POST requests” to target “IP addresses” and “ports.” XWorm also captures “screenshots” using the “CopyFromScreen” function and stores them as “JPEG” images in memory before transmission.

It executes a wide range of commands such as “system manipulation” (“shutdown”, “reboot”, “logout”), “file operations” and “remote code execution” via PowerShell. It can download and execute additional payloads such as “send HTTP requests” and “permanently install plugins”.

XWorm uses a well-defined message format for back-channel communication with the C2 server and often also adds the victim's "system information." Another feature is "process monitoring," where certain functions are performed secretly, hiding certain activities from the user.

This diverse toolkit allows actors to have extensive access and control over compromised systems, making “XWorm” a significant threat in today’s cybersecurity landscape.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Warmcookie malware promoted via fake job offers

Worms are a type of malware that replicates itself to spread to other computers. Unlike viruses, worms can propagate without the need for a host file or human interaction, making them particularly effective at spreading across networks. Once a worm has infiltrated a system, it can cause widespread damage by consuming bandwidth, deleting files, or even opening backdoors for additional attacks. Because of their ability to spread rapidly, worms can quickly and significantly disrupt both personal and professional cybersecurity. To protect against worm infections, regular software updates, strong antivirus programs, and comprehensive network monitoring are crucial.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS