XWorm v6.4 Delivery Campaign — Obfuscated JavaScript/PowerShell Loaders with ProcessHollowing DLL Injection (March 2026) — Threadlinqs Intelligence
As of 2026-05-30, XWorm v6.4 Delivery Campaign — Obfuscated JavaScript/PowerShell Loaders with ProcessHollowing DLL Injection (March 2026) is a high-severity malware threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-0180 · Severity: HIGH · Status: MONITORING · Category: MALWARE
Attribution: N/A · FINANCIAL
Active XWorm v6.4 malware delivery campaign using obfuscated JavaScript email attachments (fake invoice/packing list lures) that drop PowerShell loaders performing Base64+XOR decoding, deploying a DLL
Active XWorm v6.4 delivery campaign documented by SANS Internet Storm Center (ISC) on March 4, 2026. The attack chain begins with phishing emails containing obfuscated JavaScript attachments disguised as invoices or packing lists (e.g., "Inv-4091-CBM-4091-CUSTOM-Packing_List.js").
When executed, the JavaScript dropper writes a PowerShell loader script to the temporary directory (e.g., "ps_5uGUQcco8t5W_1772542824586.ps1"). The PowerShell loader performs multi-stage payload decoding using Base64 and XOR operations to extract the next-stage components.
The decoded payload includes a .NET DLL named "MAD.dll" that exports a function called "ProcessHollowing". This DLL acts as a loader/injector, creating a new instance of a legitimate .NET compiler process (MSBuild.exe or RegSvcs.exe) in a suspended state, hollowing out its memory, and injecting the XWorm v6.4 client payload. This process hollowing technique allows XWorm to execute within a trusted Windows process, evading application whitelisting and behavioral detection.
XWorm v6.4 is a modular Remote Access Trojan (RAT) with extensive capabilities including keystroke logging, screenshot capture, webcam access, credential theft from browsers (Chrome, Edge, Brave), file system manipulation, remote command execution, and a plugin architecture supporting dynamic loading of additional modules including ransomware (Ransomware.dll with AES-CBC encryption), shell access (Shell.dll), file management (FileManager.dll), and network monitoring (TCPConnections.dll).
The C2 server at 204.10.160.190:7003 communicates using AES-encrypted channels with the key "XAorWEAzx4+ic89KWd910w==". The malware creates a mutex "Cqu1F0NxohroKG5U" to prevent multiple instances and drops a copy as "USB.exe" for persistence and USB spreading.
Persistence is achieved through multiple mechanisms: Windows Registry Run keys (HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run), scheduled tasks, startup folder entries, and logon scripts. XWorm v6.0+ includes an AMSI bypass that modifies CLR.DLL in memory by nulling out the "AmsiScanBuffer" string. When running with administrative privileges, the malware marks itself as a critical system process, causing a system crash/reboot upon termination attempts.
Plugin storage occurs in the Windows Registry under HKCU\SOFTWARE\<CLIENT_ID> as Gzip-compressed REG_BINARY values. The modular architecture allows operators to remotely load and execute additional DLL payloads entirely in memory.
This campaign shares the same C2 infrastructure (204.10.160.190:7003) with a prior Fake FedEx phishing campaign documented by SANS ISC on February 27, 2026 (diary #32754), which used a different delivery mechanism (batch script -> PowerShell -> DonutLoader -> process injection into explorer.exe) but delivered the same XWorm variant. The infrastructure overlap indicates a persistent threat actor reusing C2 infrastructure across multiple campaign themes.
---
**Revalidated on 2026-03-12**
This threat has been fully revalidated and confirmed ACTIVE with HIGH severity maintained. The XWorm v6.4 campaign documented in TL-2026-0180 is corroborated by the original SANS ISC diary (March 4, 2026) and represents one wave in a sustained XWorm offensive that has escalated dramatically since V6.0's release in June 2025. Key revalidation findings:
**Threat Evolution**: XWorm has progressed from V5.6 (retired late 2024) through V6.0 (June 2025), V6.4 (documented here), V6.5, to V7.2 (late 2025/early 2026). Each version enhanced evasion capabilities while maintaining the core ProcessHollowing injection technique used in this campaign. V6.0+ introduced 35+ plugins including ransomware (NoCry overlap), HVNC, DDoS, USB propagation, and cryptocurrency clipboard hijacking. The plugin architecture now supports 50+ modules.
**Parallel Active Campaigns (January-March 2026)**: Multiple concurrent XWorm campaigns are active: (1) LATAM-targeting fake Bradesco bank receipt campaign using steganographic Cloudina
Target sectors: financial, manufacturing, logistics, retail, healthcare, technology, government
Target regions: North America, Europe, Asia Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1059, T1059, T1059, T1204, T1547, T1053, T1055, T1055, T1140