⤷ Title: MySQL Servers Under Attack: Threat Actors Exploiting UDFs to Inject Gh0stRAT, XWorm & Zoho Agents
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:30:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyberattack #cybersecurity #database security #Gh0stRAT #HpLoader #mysql #Remote Access Trojan #UDF #User Defined Functions #XWorm #Zoho ManageEngine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:30:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyberattack #cybersecurity #database security #Gh0stRAT #HpLoader #mysql #Remote Access Trojan #UDF #User Defined Functions #XWorm #Zoho ManageEngine
Daily CyberSecurity
MySQL Servers Under Attack: Threat Actors Exploiting UDFs to Inject Gh0stRAT, XWorm & Zoho Agents
Threat actors are actively compromising poorly managed MySQL servers, using UDFs to inject Gh0stRAT, XWorm, HpLoader, and legitimate Zoho agents for full system control and data theft.
⤷ Title: SERPENTINE#CLOUD: Stealthy Malware Campaign Leverages Cloudflare Tunnels for In-Memory RAT Delivery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 07:03:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Cloudflare Tunnel #cybersecurity #GuLoader #In_Memory Execution #LNK File #malware #phishing #PureLogs Stealer #rat #Remcos #Remote Access Trojan #Revenge RAT #Securonix #SERPENTINE#CLOUD #Venom RAT #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 07:03:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Cloudflare Tunnel #cybersecurity #GuLoader #In_Memory Execution #LNK File #malware #phishing #PureLogs Stealer #rat #Remcos #Remote Access Trojan #Revenge RAT #Securonix #SERPENTINE#CLOUD #Venom RAT #XWorm
Daily CyberSecurity
SERPENTINE#CLOUD: Stealthy Malware Campaign Leverages Cloudflare Tunnels for In-Memory RAT Delivery
The SERPENTINE#CLOUD campaign exploits Cloudflare Tunnel subdomains and LNK files to deliver in-memory RATs like AsyncRAT and Remcos, evading detection.
⤷ Title: Blind Eagle Linked to Russian Host Proton66 in Latin America Attacks
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 12:50:42 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Security #APT_C_36 #Blind Eagle #Cyber Attack #Cybersecurity #Latin America #Proton66 #Russia #XWorm
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 12:50:42 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Security #APT_C_36 #Blind Eagle #Cyber Attack #Cybersecurity #Latin America #Proton66 #Russia #XWorm
Hackread
Blind Eagle Linked to Russian Host Proton66 in Latin America Attacks
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: XWorm’s Shape-Shifting Arsenal: RAT Evolves to Deliver LockBit Ransomware, Evades Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 01:33:36 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #DLL side_loading #ETW Tampering #LockBit #malware #Process injection #ransomware #rat #Remote Access Trojan #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 01:33:36 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #DLL side_loading #ETW Tampering #LockBit #malware #Process injection #ransomware #rat #Remote Access Trojan #XWorm
Daily CyberSecurity
XWorm's Shape-Shifting Arsenal: RAT Evolves to Deliver LockBit Ransomware, Evades Detection
Splunk uncovers XWorm's evolution: a modular RAT now delivering LockBit ransomware. It uses flexible delivery, AMSI/ETW bypasses, and process injection to evade detection.
⤷ Title: XWorm 6.0: New Variant Uses AMSI Bypass & Critical Process Trick to Evade Detection and Crash Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 00:40:16 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #evasion #malware #persistence #rat #Remote Access Trojan #XWorm #XWorm 6.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 00:40:16 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #evasion #malware #persistence #rat #Remote Access Trojan #XWorm #XWorm 6.0
Daily CyberSecurity
XWorm 6.0: New Variant Uses AMSI Bypass & Critical Process Trick to Evade Detection and Crash Systems
Netskope uncovers XWorm 6.0, a new variant using VBScript droppers, AMSI bypass, and critical process marking to evade detection and force system reboots if terminated.
⤷ Title: XWorm 6.0 Unleashed: New Variant Uses AMSI Bypass & Critical Process Trick to Evade Detection and Crash Systems
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 08:08:28 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #Evasion #malware #persistence #RAT #Remote Access Trojan #XWorm #XWorm 6.0
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 08:08:28 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #Evasion #malware #persistence #RAT #Remote Access Trojan #XWorm #XWorm 6.0
Penetration Testing Tools
XWorm 6.0 Unleashed: New Variant Uses AMSI Bypass & Critical Process Trick to Evade Detection and Crash Systems
Netskope uncovers XWorm 6.0, a new variant using VBScript droppers, AMSI bypass, and critical process marking to evade detection and force system reboots if terminated.
⤷ Title: CYBERDEFENDERS XWorm Lab
════════════════════════
𐀪 Author: Habibecanan
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 09:41:23 GMT
════════════════════════
⌗ Tags: #writeup #blue_team #cybersecurity #cyberdefenders_writeup #xworm
════════════════════════
𐀪 Author: Habibecanan
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 09:41:23 GMT
════════════════════════
⌗ Tags: #writeup #blue_team #cybersecurity #cyberdefenders_writeup #xworm
Medium
CYBERDEFENDERS XWorm Lab
Link: https://cyberdefenders.org/blueteam-ctf-challenges/xworm/
⤷ Title: A Deceptive AI Lure Is Hiding ScreenConnect & XWorm RAT to Hijack Your PC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:20:42 +0000
════════════════════════
⌗ Tags: #Malware #AI #cybersecurity #Hacking #malware #ScreenConnect #social engineering #Trustwave #XWorm RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:20:42 +0000
════════════════════════
⌗ Tags: #Malware #AI #cybersecurity #Hacking #malware #ScreenConnect #social engineering #Trustwave #XWorm RAT
Daily CyberSecurity
A Deceptive AI Lure Is Hiding ScreenConnect & XWorm RAT to Hijack Your PC
A new campaign is using fake AI-themed content to trick users into downloading a malicious ScreenConnect installer that secretly delivers the XWorm Remote Access Trojan.
⤷ Title: Beyond Simple Scripts: A New XWorm Campaign Uses Multi-Stage Stealth
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 00:05:39 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Cybercrime #cybersecurity #LNK File #malware #phishing #Trellix #windows #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 00:05:39 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Cybercrime #cybersecurity #LNK File #malware #phishing #Trellix #windows #XWorm
Daily CyberSecurity
Beyond Simple Scripts: A New XWorm Campaign Uses Multi-Stage Stealth
A new report reveals a sophisticated XWorm backdoor campaign that uses .lnk files and a multi-stage infection chain to gain stealthy and persistent control of Windows systems.
⤷ Title: The Art of Digital Evasion: How Attackers Hide in Plain Sight
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 08:35:29 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evasion #hacking #HP Wolf Security #Living_off_the_land #LOTL #Lumma Stealer #malware #Threat Actors #XWorm
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 08:35:29 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evasion #hacking #HP Wolf Security #Living_off_the_land #LOTL #Lumma Stealer #malware #Threat Actors #XWorm
Penetration Testing Tools
The Art of Digital Evasion: How Attackers Hide in Plain Sight
A new report from HP Wolf Security reveals how cybercriminals are using "living-off-the-land" tactics and hiding malware in images and SVG files to evade detection.
⤷ Title: Hackers Use Fake Invoices to Spread XWorm RAT via Office Files
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 10:57:09 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cybersecurity #Invoice #Microsoft Office #Phishing #RAT #TROJAN #Windows #XWorm
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 10:57:09 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cybersecurity #Invoice #Microsoft Office #Phishing #RAT #TROJAN #Windows #XWorm
Hackread
Hackers Use Fake Invoices to Spread XWorm RAT via Office Files
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: XWorm V6.0 Resurfaces: Modular RAT Returns with Ransomware Plugin and Advanced Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 04 Oct 2025 00:00:32 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #ransomware #rat #Remote Access Trojan #Trellix #windows #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 04 Oct 2025 00:00:32 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #ransomware #rat #Remote Access Trojan #Trellix #windows #XWorm
Daily CyberSecurity
XWorm V6.0 Resurfaces: Modular RAT Returns with Ransomware Plugin and Advanced Evasion
XWorm V6.0 has resurfaced with 35+ plugins, including ransomware functionality. The modular RAT uses stealth injection and obfuscated PowerShell to bypass AMSI.
⤷ Title: Top 3 Malware Families in Q4: How to Keep Your SOC Ready
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 12:05:34 +0000
════════════════════════
⌗ Tags: #Malware #Security #Agent Tesla #ANY RUN #Cybersecurity #Lumma Stealer #SOC #Threat Intelligence #Vulnerability #XWorm
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 12:05:34 +0000
════════════════════════
⌗ Tags: #Malware #Security #Agent Tesla #ANY RUN #Cybersecurity #Lumma Stealer #SOC #Threat Intelligence #Vulnerability #XWorm
Hackread
Top 3 Malware Families in Q4: How to Keep Your SOC Ready
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: The “D” is for Danger: How a Tiny Typo in MAS Activation Hijacks Your PC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:55:46 +0000
════════════════════════
⌗ Tags: #Malware #Cosmali Loader #Cyber Attack 2025 #malware #MAS #Microsoft Activation Scripts #powershell #Typosquatting #Windows Security #XWorm RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:55:46 +0000
════════════════════════
⌗ Tags: #Malware #Cosmali Loader #Cyber Attack 2025 #malware #MAS #Microsoft Activation Scripts #powershell #Typosquatting #Windows Security #XWorm RAT
Daily CyberSecurity
The "D" is for Danger: How a Tiny Typo in MAS Activation Hijacks Your PC
Attackers are using a fake MAS domain (get.activate.win) to deploy Cosmali Loader and XWorm RAT via PowerShell. Verify your command before running it!
⤷ Title: The “Phantom” Resurrection: How Intrinsec Unmasked the Mandark-Powered Malware Loader Evading Global Defense
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:48:37 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #cybersecurity news #DarkCloud #Intrinsec #IoCs 2026 #Mandark utility #PhantomVAI #Process Hollowing #Remcos #RunPE framework #Threat Hunting #XWorm #YARA rules
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:48:37 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #cybersecurity news #DarkCloud #Intrinsec #IoCs 2026 #Mandark utility #PhantomVAI #Process Hollowing #Remcos #RunPE framework #Threat Hunting #XWorm #YARA rules
Penetration Testing Tools
The "Phantom" Resurrection: How Intrinsec Unmasked the Mandark-Powered Malware Loader Evading Global Defense
Analysts at Intrinsec have documented a surge in offensives leveraging the PhantomVAI loader, a utility architected upon the
⤷ Title: Excel Trap: New Phishing Campaign Deploys Fileless XWorm RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:13:12 +0000
════════════════════════
⌗ Tags: #Malware #CVE_2018_0802 #cybersecurity #Excel Malware #Fileless Malware #FortiGuard Labs #phishing #powershell #Process Hollowing #rat #steganography #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:13:12 +0000
════════════════════════
⌗ Tags: #Malware #CVE_2018_0802 #cybersecurity #Excel Malware #Fileless Malware #FortiGuard Labs #phishing #powershell #Process Hollowing #rat #steganography #XWorm
Daily CyberSecurity
Excel Trap: New Phishing Campaign Deploys Fileless XWorm RAT
Phishing emails use malicious Excel files to deploy XWorm RAT. The fileless attack exploits CVE-2018-0802 to steal data & control systems.
⤷ Title: Hackers Use Excel Exploit to Hide XWorm 7.2 in JPEG Files, Hijack PCs
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 11:54:06 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Cyber Attack #Cybersecurity #Excel #Invoice #Phishing #RAT #Scam #Windows #XWorm
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 11:54:06 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Cyber Attack #Cybersecurity #Excel #Invoice #Phishing #RAT #Scam #Windows #XWorm
Hackread
Hackers Use Excel Exploit to Hide XWorm 7.2 in JPEG Files, Hijack PCs
A new phishing campaign is spreading XWorm 7.2 via malicious Excel files, hiding malware in Windows processes to steal passwords and Wi-Fi keys.
⤷ Title: The Explorer Trap: How Hackers Turn Windows File Explorer into a Silent Portal for Remote Access Trojans
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 04:17:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Async RAT #Cloudflare Tunnel #Cofense Intelligence #infosec #malware #rat #Remote Access Trojan #UNC Paths #WebDAV #Windows File Explorer #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 04:17:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Async RAT #Cloudflare Tunnel #Cofense Intelligence #infosec #malware #rat #Remote Access Trojan #UNC Paths #WebDAV #Windows File Explorer #XWorm
Daily CyberSecurity
The Explorer Trap: How Hackers Turn Windows File Explorer into a Silent Portal for Remote Access Trojans
Cofense uncovers a stealthy campaign abusing legacy WebDAV in Windows File Explorer to bypass browsers and EDR, delivering XWorm and Async RAT via UNC paths.