Researchers at Point Wild reported a malware campaign that abuses the legitimate packaging tool PyInstaller to disguise and deliver XWorm RAT v7.4 inside files presented as benign software or updates. The infection chain uses obfuscation and anti-analysis techniques, including a routine identified as _IAT_PHANTOM_FIX, then patches AMSI in memory to weaken Windows scanning before unpacking an encrypted payload. The malware is then dropped into %LOCALAPPDATA% as the hidden system file Win.Kernel_Svc_AJ8iOw.exe, helping it evade user notice and endpoint defenses.
Once installed, the payload connects to command-and-control infrastructure at 68.219.64.89:4444 using an AES key and enables a broad set of remote-access capabilities. Point Wild said XWorm can steal passwords, access files, activate webcams, launch DDoS attacks, and provide full remote control; researchers also observed deployment of an additional file, afacan313131.exe, as part of the intrusion. The findings show how attackers are combining trusted developer tools with memory patching and encrypted payload delivery to make a well-known malware family harder to detect.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
The researchers reported that the payload drops as a hidden file named "Win.Kernel_Svc_AJ8iOw.exe" in %LOCALAPPDATA% and connects to command-and-control server 68.219.64.89 on port 4444 using an AES key. They said the XWorm V7.4 infection enables password theft, file access, webcam spying, DDoS activity, and full remote control, including deployment of an additional file named afacan313131.exe.
Point Wild researchers uncovered a malware campaign that abuses the legitimate PyInstaller packaging tool to disguise and deliver XWorm RAT through deceptive emails or fake software updates. The attack chain uses obfuscation, anti-analysis routines, AMSI memory patching, and encrypted payload unpacking to evade detection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.