Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Attack chain leads to XWORM and AGENTTESLA

released on 2023-04-10 @ 03:24:21 PM
A new malware campaign employs a well-developed process with multiple stages. The campaign is designed to trick unsuspecting users into clicking on the documents, which appear to be legitimate, but are in fact fake, the adversary leverages weaponized word documents to execute malicious PowerShell scripts, and also utilizes a custom obfuscated .NET loader to load various malware strains, including XWORM and AGENTTESLA.