Researcher Exposes XWorm Malwareโs C2 Communication
DUBAI, UNITED ARAB EMIRATES, November 27, 2023 /EINPresswire.com/ -- ANY.RUN, a leading malware analysis sandbox provider, has published a research article by Igal Lytzki (0xToxin on Twitter) in its blog, detailing the inner workings of the XWorm malware, a Remote Access Trojan (RAT) targeting Windows systems. The analysis delves into the communication between the XWorm server and infected clients, revealing the malware's data theft and remote-control capabilities.
๐๐๐๐ซ๐ฒ๐ฉ๐ญ๐ข๐ง๐ ๐๐๐จ๐ซ๐ฆ'๐ฌ ๐๐๐๐ฎ๐ซ๐๐ ๐๐จ๐ฆ๐ฆ๐ฎ๐ง๐ข๐๐๐ญ๐ข๐จ๐ง
The research found that XWorm uses AES-ECB encryption to communicate with its command-and-control (C2) server.
By decrypting this data, Lytzki was able to analyze the information exchanged between the malware and its server. This revealed that the malware collects sensitive information such as username, machine name, OS version, webcam presence, CPU and GPU details, installed antivirus software, and more.
๐๐ง๐๐จ๐ฏ๐๐ซ๐ข๐ง๐ ๐๐๐จ๐ซ๐ฆ'๐ฌ ๐๐๐ฆ๐จ๐ญ๐ ๐๐จ๐ง๐ญ๐ซ๐จ๐ฅ ๐ ๐๐๐ญ๐ฎ๐ซ๐๐ฌ
The researcher also discovered two plugins that can be activated through remote control of infected systems:
โข Info stealer plugin: This plugin steals sensitive data, including credit card information, Chromium cookies, Discord tokens, FileZilla credentials, browser data, browser history, WiFi passwords, MetaMask data, and Telegram data.
โข Commands plugin: This plugin enables attackers to execute various malicious actions, such as disabling or terminating Windows Defender, excluding paths from Windows Defender scans, installing the .NET framework, and blanking the screen.
๐๐ญ๐ข๐ฅ๐ข๐ณ๐ข๐ง๐ ๐๐๐ฐ ๐๐ง๐ฌ๐ข๐ ๐ก๐ญ๐ฌ ๐๐จ๐ซ ๐๐๐จ๐ซ๐ฆ ๐๐๐ญ๐๐๐ญ๐ข๐จ๐ง
The information gathered during the research has been integrated into the ANY.RUN sandbox, improving its detection capabilities.
Learn more in ANY.RUNโs blog.
Vlada Belousova
ANYRUN FZCO
2027889264
email us here
Visit us on social media:
Twitter
YouTube
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
