#XWorm

Malware/Tool

2025-05-12 • Analysis of Kimsuky APT Group (Powershell Payloads one of them attributed to XWorm RAT)

After decoding, the analyzed script was observed downloading several files, including RAR archives and executables, from a single IP address. The report connects the sample with Kimsuky-related PowerShell activity and says both analyzed payloads were used to obtain an RDP connection to the victim’s actual IP while bypassing hypervisors. A referenced process tree begins with powershell.exe and proceeds through a broader execution chain.

Tagged Reports

« Back