FILEMembers
FILE

XWorm Worm Campaign Hits 24 Countries via Spanish Quotation Lure

A 914-kilobyte executable disguised as a Spanish-language purchase-order request is spreading XWorm and PureLog Stealer across 24 countries. The campaign pairs anti-sandbox evasion with a USB-spreader module capable of carrying the infection to air-gapped machines, backed by bulletproof C2 infrastructure under offshore-registered shell entities.

May 27, 2026, 01:21 (UTC+9)Last seenMay 27, 2026Severity100ByCTX TeamIOC15MITRE32RegionsATBECACHCO

A 914-kilobyte Windows executable masquerading as a Spanish-language purchase-order request is circulating across 24 countries, carrying a payload combination that goes well beyond what most commodity-RAT deployments attempt: XWorm and PureLog Stealer bundled together, wrapped in a PEiD-packed binary with a .text section entropy of 7.83, and equipped with a worm-propagation module that can copy the infection to removable media without any additional operator action.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence