Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
XWorm Malware Targets Latin American Businesses

XWorm Malware Targets Latin American Businesses

Posted on February 19, 2026 By CWS

The XWorm malware campaign has been identified as a significant threat targeting businesses in Brazil and across Latin America. This operation employs fake financial receipts to distribute XWorm v5.6, a sophisticated remote access trojan (RAT) with capabilities to steal credentials, hijack user sessions, and facilitate ransomware attacks.

Deceptive Distribution Techniques

Researcher Moises Cerqueira uncovered that the campaign begins with a deceptive file named to resemble a Bradesco bank receipt. This file uses a double-extension trick (.pdf.js) to disguise itself as a legitimate PDF, tricking unsuspecting users into opening it. However, the file is actually a Windows Script Host (WSH) dropper, inflated to approximately 1.2MB to evade static analysis by security scanners.

The embedded JavaScript payload is obfuscated using Unicode junk injection, embedding harmful logic within strings filled with emojis and non-ASCII characters. This obfuscation tactic is designed to bypass standard security controls and ensure the malware’s successful execution.

Advanced Malware Execution Strategy

Once executed, the malware uses PowerShell commands to download additional stages from a Cloudinary URL, a trusted image hosting service. This stage involves downloading an image file that conceals a .NET assembly, bypassing traditional antivirus checks through a fileless execution technique.

The subsequent stages involve reconstructing the malicious payload using a delimiter-based method and leveraging Windows Management Instrumentation (WMI) to execute PowerShell commands discreetly. This method minimizes visibility and enables the malware to operate without drawing attention from standard security monitoring tools.

Implications and Defense Strategies

The final stage involves the deployment of XWorm v5.6, which uses the legitimate CasPol.exe binary to blend with trusted processes. This ‘Living off the Land’ technique allows the malware to avoid detection while accessing sensitive information, such as browser sessions and credentials.

Security experts recommend organizations implement monitoring controls to detect such sophisticated attacks. This includes alerting on double-extension files initiating PowerShell processes, flagging suspicious network traffic, and thoroughly investigating any anomalies involving CasPol.exe.

To mitigate risks, businesses should prioritize real-time threat detection and response capabilities. By understanding the tactics employed in this campaign, organizations can better defend against similar threats and protect their critical assets from cybercriminal activities.

Cyber Security News Tags:credential theft, cyber attack, Cybersecurity, fake receipts, LATAM, Malware, Ransomware, remote access trojan, Windows, XWorm

Post navigation

Previous Post: Figure Tech Data Breach Exposes 1 Million User Records
Next Post: Ivanti Vulnerabilities Exploited in Recent Cyber Attacks

Related Posts

Cybercriminals Exploit Legitimate Platforms for Ransomware Cybercriminals Exploit Legitimate Platforms for Ransomware Cyber Security News
Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger Cyber Security News
ToolShell Exploit Chain Attacking SharePoint Servers to Gain Complete Control ToolShell Exploit Chain Attacking SharePoint Servers to Gain Complete Control Cyber Security News
Attack Techniques of Tycoon 2FA Phishing Kit Targeting Microsoft 365 and Gmail Accounts Detailed Attack Techniques of Tycoon 2FA Phishing Kit Targeting Microsoft 365 and Gmail Accounts Detailed Cyber Security News
Matanbuchus Malware Downloader Evading AV Detections by Changing Components Matanbuchus Malware Downloader Evading AV Detections by Changing Components Cyber Security News
Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenSSL Vulnerabilities and Emerging Cyber Threats
  • Hackers Use Emoji Code to Evade Security Systems
  • Ivanti Vulnerabilities Exploited in Recent Cyber Attacks
  • XWorm Malware Targets Latin American Businesses
  • Figure Tech Data Breach Exposes 1 Million User Records

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenSSL Vulnerabilities and Emerging Cyber Threats
  • Hackers Use Emoji Code to Evade Security Systems
  • Ivanti Vulnerabilities Exploited in Recent Cyber Attacks
  • XWorm Malware Targets Latin American Businesses
  • Figure Tech Data Breach Exposes 1 Million User Records

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News