Want More XWorm?, (Wed, Mar 4th)

2026-03-04T19:23:54Zee54f18d0aee9be6bb099c8d4aaa7ff0cd6ef43645d2d0c6e0294bc39895e271
CVE-2024-4040CVE-2025-31161CVE-2025-54309bruteforcecrushftpcvemalwaremalware-deliveryphishingrtfthreat-actorvulnerabilitywiresharkxworm

What happened

SANS ISC feed notes an ongoing wave of XWorm infections using multi-technology payloads and evolving delivery techniques, highlighting that prolific malware families continue to adapt. Separate entries report brute-force scans targeting CrushFTP and call out earlier serious CrushFTP vulnerabilities (including an actively exploited 2025 zero-day). Other items include a phishing campaign masquerading as FedEx that delivered malware, a how-to on extracting ZIPs from RTFs (relevant to document-based delivery), and a Wireshark 4.6.4 release that fixes multiple vulnerabilities. Organizations should:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
ee54f18d0aee9be6bb099c8d4aaa7ff0cd6ef43645d2d0c6e0294bc39895e271
Enrichment time
2026-03-04T19:23:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Want More XWorm?, (Wed, Mar 4th) · Baitaphish