FILEMembers
FILE

vjw0rm Worm's Full Dropper Chain Resurfaces Five Years Later

Nine indicators let researchers reconstruct an entire LNK-to-batch-to-AutoIT dropper chain for the commodity vjw0rm worm, ending in a conhost.exe-masquerading payload that calls home via a free dynamic-DNS domain. The chain, loosely tied to TA2541 and aimed at Thai manufacturing targets, survives unchanged from a 2021 sample set into a 2026 build compiled a decade earlier.

Jul 20, 2026, 21:46 (UTC+9)Last seenJul 20, 2026Severity100ByCTX TeamActorTA2541Operation LayoverIOC11RegionsTH

Nine file indicators tied to the vjw0rm worm family let CTX Team reconstruct, almost stage by stage, how this decade-old commodity malware still moves through a target environment in 2026: a booby-trapped Windows shortcut hands off to a batch script, which drops an AutoIT-compiled payload dressed up as a core Windows process, which then calls home to a free dynamic-DNS domain.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence