Researchers at Point Wild reported a malware campaign that abuses the legitimate packaging tool PyInstaller to disguise and deliver XWorm RAT v7.4 inside files presented as benign software or updates. The infection chain uses obfuscation and anti-analysis techniques, including a routine identified as _IAT_PHANTOM_FIX, then patches AMSI in memory to weaken Windows scanning before unpacking an encrypted payload. The malware is then dropped into %LOCALAPPDATA% as the hidden system file Win.Kernel_Svc_AJ8iOw.exe, helping it evade user notice and endpoint defenses.
Once installed, the payload connects to command-and-control infrastructure at 68.219.64.89:4444 using an AES key and enables a broad set of remote-access capabilities. Point Wild said XWorm can steal passwords, access files, activate webcams, launch DDoS attacks, and provide full remote control; researchers also observed deployment of an additional file, afacan313131.exe, as part of the intrusion. The findings show how attackers are combining trusted developer tools with memory patching and encrypted payload delivery to make a well-known malware family harder to detect.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The researchers reported that the payload drops as a hidden file named "Win.Kernel_Svc_AJ8iOw.exe" in %LOCALAPPDATA% and connects to command-and-control server 68.219.64.89 on port 4444 using an AES key. They said the XWorm V7.4 infection enables password theft, file access, webcam spying, DDoS activity, and full remote control, including deployment of an additional file named afacan313131.exe.
Point Wild researchers uncovered a malware campaign that abuses the legitimate PyInstaller packaging tool to disguise and deliver XWorm RAT through deceptive emails or fake software updates. The attack chain uses obfuscation, anti-analysis routines, AMSI memory patching, and encrypted payload unpacking to evade detection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.