
One Imphash, Two Malware Families: Inside a Shared .NET Builder
A purchase-order spear-phishing campaign active since May 2026 has delivered XWorm RAT and AgentTesla infostealer from a single .NET builder kit, confirmed by an identical PE import-table hash across both payloads. The operation spans 35 countries and 13 industry verticals, with C2 anchored to a freshly provisioned Turkish cloud node bearing a self-signed certificate tied to the actor-controlled domain wembolsar.com. A zero-detection C# source file appearing in sandbox temp directories hints at a possible compile-on-victim capability.
A purchase-order-themed spear-phishing campaign active since mid-May 2026 has delivered something more operationally revealing than its commodity tooling alone would suggest: two functionally distinct malware families — XWorm RAT and AgentTesla infostealer — sharing an identical PE import-table hash (imphash f34d5f2d4577ed6d9ceec516c1f5a744) and the same PEiD packer signature, confirming both were produced by a single .NET builder kit or shared loader stub.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read