
vjw0rm Worm's Full Dropper Chain Resurfaces Five Years Later
Nine indicators let researchers reconstruct an entire LNK-to-batch-to-AutoIT dropper chain for the commodity vjw0rm worm, ending in a conhost.exe-masquerading payload that calls home via a free dynamic-DNS domain. The chain, loosely tied to TA2541 and aimed at Thai manufacturing targets, survives unchanged from a 2021 sample set into a 2026 build compiled a decade earlier.
Nine file indicators tied to the vjw0rm worm family let CTX Team reconstruct, almost stage by stage, how this decade-old commodity malware still moves through a target environment in 2026: a booby-trapped Windows shortcut hands off to a batch script, which drops an AutoIT-compiled payload dressed up as a core Windows process, which then calls home to a free dynamic-DNS domain.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read