XWorm v5.6 Targets LATAM via Fake Bank Receipts
VPN Central [Unofficial]
February 20, 2026
XWorm v5.6 malware spreads through fake Bradesco bank receipts targeting Brazilian and LATAM businesses. The campaign delivers a multi-stage RAT that steals credentials, hijacks browser sessions, and sets up ransomware staging. Researcher Moises Cerqueira uncovered the sophisticated infection chain. Attackers disguise droppers as PDFs using .pdf.js double extensions. Files inflate to 1.2MB with junk Unicode […]
The post XWorm v5.6 Targets LATAM via Fake Bank Receipts appeared first on VPN Central.
Discussion in the ATmosphere