No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

XWorm, Remcos RAT Evade EDRs to Infect Critical Infrastructure

August 13, 2023
in Protection
0
informa



The Rust-based injector Freeze[.]rs has been weaponized to introduce a raft of malware to targets, in a sophisticated phishing campaign containing a malicious PDF file that gets around endpoint detection and response (EDR).

First discovered by Fortinet’s FortiGuard Labs in July, the campaign is targeting victims across Europe and North America, including specialty chemical or industrial product suppliers.

Eventually, this chain culminates in the loading of XWorm malware establishing communication with a command-and-control (C2) server, an analysis by the firm revealed. XWorm can carry out a wide range of functions, from loading ransomware to acting as a persistent backdoor.

Further revelations also unveiled the involvement of SYK Crypter, a tool frequently utilized to distribute malware families via the Discord community chat platform. This crypter played a role in loading Remcos, a sophisticated remote access Trojan (RAT) adept at controlling and monitoring Windows devices.

Putting EDR on Ice: Under the Hood of the Freeze[.]rs Attack Chain

In their investigation, the team’s analysis of encoded algorithms and API names traced the origin of this novel injector back to the Red Team tool “Freeze.rs,” designed explicitly for crafting payloads capable of bypassing EDR security measures.

“This file redirects to an HTML file and utilizes the ‘search-ms’ protocol to access an LNK file on a remote server,” a company blog post explained. “Upon clicking the LNK file, a PowerShell script executes Freeze[.]rs and SYK Crypter for further offensive actions.”

Cara Lin, researcher, FortiGuard Labs, explains that the Freeze[.]rs injector calls NT syscalls to inject the shellcode, skipping the standard calls that are in Kernel base dll, which may be hooked.

“They use the slight delay that occurs before an EDR starts hooking and altering the assembly of system DLLs within a process,” she says. “If a process is created in a suspended state, it has minimal DLLs loaded, and no EDR-specific DLLs are loaded, indicating that the syscalls within Ntdll.dll remain unaltered.”

Lin explains the attack chain is initiated through a booby-trapped PDF file, which works together with a “search-ms” protocol to deliver the payload.

This JavaScript code utilized the “search-ms” functionality to reveal the LNK file located on a remote server.

The “search-ms” protocol can redirect users to a remote server via a Windows Explorer Window.

“Through the use of a deceptive LNK file disguised as a PDF icon, it can deceive victims into believing that the file originates from their own system and is legitimate,” she notes.

Meanwhile, “the SYK Crypter copies itself to the Startup folder for persistence, encrypts the configuration during encoding and decrypts it upon execution, and also encrypts the compressed payload in the resource‎‎ for obfuscation,” she adds.

A downloader is utilized alongside encoding in the first layer and subsequently, a second layer involves string obfuscation and payload encryption.

“This multi-layered strategy is designed to enhance the complexity and challenge for static analysis,” she says. “Finally, it can terminate itself upon recognizing a specific security vendor.”

How to Defend Against Mounting Phishing Risk

Phishing and other messaging-based attacks continue to be a pervasive threat, with 97% of companies seeing at least one email phishing attack in the past 12 months and three-quarters of firms expecting significant costs from an email-based attack.

Phishing attacks are getting smarter and more targeted, adapting to new technology and user behavior, evolving to include mobile exploits, brand impersonation, and AI-generated content.

The research notes its crucial to maintain up-to-date software to mitigate risks, provide regular training, and use advanced security tools for defenses to counter the evolving threat of phishing attacks.

Phishing simulation training for employees appears to work better at critical infrastructure organizations than it does across other sectors, with 66% of those employees correctly reporting at least one real malicious email attack within a year of training, new research has found.

Editorial Team

Editorial Team

Related Posts

The Google Nest Wifi Pro Mesh System Is $170 Off Right Now
Protection

The Google Nest Wifi Pro Mesh System Is $170 Off Right Now

May 14, 2026
The Samsung Galaxy S25+ Is One of the Best Premium Android Phones, and It's $300 Off Right Now
Protection

The Samsung Galaxy S25+ Is One of the Best Premium Android Phones, and It’s $300 Off Right Now

May 14, 2026
Three Things I Already Like About the Fitbit Air
Protection

Three Things I Already Like About the Fitbit Air

May 14, 2026
Mark Zuckerberg Just Teased New Smart Glasses Ahead of Meta Connect
Protection

Mark Zuckerberg Just Teased New Smart Glasses Ahead of Meta Connect

May 13, 2026
The Beats Studio Pro Headphones Are on Sale for $160 Right Now
Protection

The Beats Studio Pro Headphones Are on Sale for $160 Right Now

May 13, 2026
You Could Get up to $100 in This Google Class Action Lawsuit
Protection

You Could Get up to $100 in This Google Class Action Lawsuit

May 13, 2026
Load More
Next Post
Nikola Recalls Most of Its Battery-Electric Trucks After Fire Probe

Nikola Recalls Most of Its Battery-Electric Trucks After Fire Probe

Popular News

  • Bitmine takes BMNR to NYSE with $4 billion buyback expansion

    Bitmine takes BMNR to NYSE with $4 billion buyback expansion

    0 shares
    Share 0 Tweet 0
  • Analyst Says High XRP Price Targets Are Dangerous, Here’s Why

    0 shares
    Share 0 Tweet 0
  • ¿Debiera usted ayudar económicamente a sus hijos adultos?

    0 shares
    Share 0 Tweet 0
  • HAMISH MCRAE: Time to fix Gordon Brown’s pension errors

    0 shares
    Share 0 Tweet 0
  • JPMorgan’s markets and investment banking revenue surge, but here’s why the stock is pulling back

    0 shares
    Share 0 Tweet 0

Latest News

Claude helps man recover 5 Bitcoin after old wallet search - 1

Claude helps man recover 5 Bitcoin after old wallet search

May 14, 2026
0

An X user known as Cprkrn says Anthropic’s Claude helped him recover 5 Bitcoin from a wallet he had not...

Intel shares surge 214%, short sellers face $12B in losses

Intel shares surge 214%, short sellers face $12B in losses

May 14, 2026
0

Intel has been on an absolute tear since March 2023, rallying 214% and adding over $440 billion in market capitalization....

Stablecoins Enter Institutional Phase As Senate CLARITY Draft Clarifies Rules – Analyst

Stablecoins Enter Institutional Phase As Senate CLARITY Draft Clarifies Rules – Analyst

May 14, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The crypto market faces a pivotal regulatory...

Morning Bid: AI rally powers on, Trump-Xi summit takes centre stage

Morning Bid: AI rally powers on, Trump-Xi summit takes centre stage

May 14, 2026
0

Morning Bid: AI rally powers on, Trump-Xi summit takes centre stage

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.