The research found that XWorm uses AES-ECB encryption to communicate with its command-and-control (C2) server. By decrypting this data, Lytzki was able to analyze the information exchanged between the ...
A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access ...