meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, March 5th, 2026: XWorm Analysis; Cisco “Secure” Firewall Managmeent Center; LastPass Phishing

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 5 March 2026

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, March 5th, 2026: XWorm Analysis; Cisco “Secure” Firewall Managmeent Center; LastPass Phishing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, March 5th, 2026 edition of the Sands Internet Storm Centers, Stormcast.

0:12.9

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.0

And this episode is brought you by the sands.edu graduate certificate program in

0:22.9

Purple Team Operations. Well, Xavier today is asking, do you want more X-Worm? Because that's the sample

0:31.3

that Xavier is looking at today, including the infection chain that actually gets you to the actual X-Worm sample.

0:40.1

Ex-Worm remains one of the favorite payloads deployed by the miscreants out there,

0:46.9

starts in this case with a simple fishing email that has, well, yet again, a seven-sip attachment.

0:53.8

That unsips then to JavaScript, and we have seen this now

0:58.4

for so many years, this sort of compressed JavaScript thing, not sure why filters or so

1:04.6

don't really catch on to this yet. Then it becomes PowerShell, and then it actually injects itself into the Dotnet

1:13.3

compiler. That's sort of where it loads the DLL until it loads the actual X-Worm payload.

1:19.9

So somewhat convoluted, the infection chain here, Xavier walks you through the reverse analysis

1:26.2

of this particular sample,

1:28.9

how to get from the JavaScript, which actually Xavier just executes in the sandbox,

1:33.7

all the way to the X-form payload.

1:37.8

And another problem that has been haunting us for years now is malicious search engine optimization, where attackers are either outright

1:46.4

buying ads in search engines or they are placing content around the internet that in all

1:52.6

points to malicious content if a particular user is searching for a popular term. Well, this is now

2:00.4

happening also with some of the AI search engines.

2:03.8

Many search engines, Google, Bing, Yahoo, they all now have these AI search engines,

2:09.8

and you probably have all seen them where you search for something. And at the top of the page,

2:14.7

you'll get sort of that little AI blurb trying to summarize

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.