#xworm #opendir at:
c2: 151.241.154\.23:7007
— from @James_inthe_box (https://x.com/James_inthe_box/status/2107491399730073763)

#xworm #opendir at:
c2: 151.241.154\.23:7007
— from @James_inthe_box (https://x.com/James_inthe_box/status/2107491399730073763)
2CLoader malware dodges sandboxes and security tools to deliver Vidar and Remus infostealers. See how it works and how to detect it.
#2CLoader #Vidar #Remus #XWorm #Infostealer #MalwareLoader #ThreatLabz #CyberSecurity
2CLoader binds its AES key to its own .text hash, then drops Vidar, Remus and XWorm. https://intel.threadlinqs.com/threat/TL-2026-2819 #ThreatIntel #XWorm #Vidar #Remus
Lua loader hides in fake .ttf font files - fileless RATs via VEH-encrypted shellcode. https://intel.threadlinqs.com/threat/TL-2026-2402 #ThreatIntel #Rakhni #Agent #XWorm