Want More XWorm?, (Wed, Mar 4th)
2026-03-04T19:23:54Z•ee54f18d0aee9be6bb099c8d4aaa7ff0cd6ef43645d2d0c6e0294bc39895e271
CVE-2024-4040CVE-2025-31161CVE-2025-54309bruteforcecrushftpcvemalwaremalware-deliveryphishingrtfthreat-actorvulnerabilitywiresharkxworm
What happened
SANS ISC feed notes an ongoing wave of XWorm infections using multi-technology payloads and evolving delivery techniques, highlighting that prolific malware families continue to adapt. Separate entries report brute-force scans targeting CrushFTP and call out earlier serious CrushFTP vulnerabilities (including an actively exploited 2025 zero-day). Other items include a phishing campaign masquerading as FedEx that delivered malware, a how-to on extracting ZIPs from RTFs (relevant to document-based delivery), and a Wireshark 4.6.4 release that fixes multiple vulnerabilities. Organizations should:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- ee54f18d0aee9be6bb099c8d4aaa7ff0cd6ef43645d2d0c6e0294bc39895e271
- Enrichment time
- 2026-03-04T19:23:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.