Recently AnyRun, a popular platform offering an interactive sandbox for malware analysis, published a technical analysis of a new version of xWorm, a remote access Trojan (RAT) sold as malware-as-a-service and known for its wide range of dangerous features.
This malware is sold on darknet forums and through the Telegram application.
Our Malware Lab therefore began monitoring public submissions on the AnyRun sandbox to ascertain how far this new version had begun to spread.
Indeed, several samples were found to have the same behaviour as the new variant.
In line with the characteristics of RATs, the client proceeds to connect to a server and is identified by generating a hash (i.e. a random sequence of characters) of some system information. Then, the client will wait for remote commands to be sent from the server.
If you wish to learn more, here is the link to our full report.
In addition, you can subscribe to the specific mailing list Cyber Studios by Tinexta Defence, to receive updates on upcoming research: https://tinextadefence.it/mailing-list-cyber-studios/