WarMachine is a likely Turkish-speaking cybercriminal threat actor associated with malware delivery campaigns distributing XWorm. Observed activity used multiple initial-access vectors, including JavaScript lures themed as tax documents, batch-file droppers with User Account Control bypass, and weaponized Microsoft Excel documents exploiting CVE-2017-11882. The actor relied on public code-hosting and file-sharing services for staging and payload delivery, a choice that complicates disruption and infrastructure takedown. The intrusion chain included obfuscated script execution, PowerShell-based retrieval of follow-on payloads, and in-memory execution of decrypted shellcode. WarMachine established persistence through Startup-folder placement, Registry Run keys masquerading as legitimate software components, and scheduled tasks. The actor also used living-off-the-land execution proxies and weakened host defenses by modifying Microsoft Defender exclusions. Payloads attributed to this activity culminated in XWorm version 6.0. In this usage, XWorm provided broad post-compromise functionality including credential theft, keylogging, screen capture, process injection, exfiltration-oriented collection, DDoS capability, and ransomware-like file encryption. The campaign also showed operational-security failures, including publicly exposed staging resources and Turkish-language artifacts, which support the assessment of a Turkish-speaking operator. WarMachine has been mentioned alongside SideWinder in reporting on campaigns using Equation Editor exploitation, but the observed WarMachine activity here is most strongly characterized as financially motivated malware distribution and post-exploitation using commodity remote-access tooling.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.