PULSE NAME
IOC - From PyInstaller to XWorm V7.4: Infection Chain Analysis
WHITE celestre 2026-05-22 Modified: 2026-05-22
7
IOCs
LOW VOLUME
Point Wild conducted an in-depth analysis of a suspicious PyInstaller-packed Python sample and identified it as a multi-stage malware loader designed to deploy the XWorm Remote Access Trojan (RAT), specifically associated with the XWorm V7.4 campaign. The sample leveraged multiple layers of obfuscation, staged execution and anti-analysis techniques to conceal its true functionality and evade detection by traditional security controls.
Indicators of Compromise (2 / 7 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 c7a6f220f2ff7d6718a5b2f0e85f13dd 2026-05-22
FileHash-MD5 d4494a5b1430f7c5347408732cdbd668 2026-05-22