Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Cybersecurity is about sharing. Recognize the risk,
combat it, share your experiences, and encourage others
to do better than you.
Banner Ancharia Mobile 1
Banner Ransomfeed 970x120 1
Storm-0900 Phishing Campaign Spreads XWorm Malware

Storm-0900 Phishing Campaign Spreads XWorm Malware

4 December 2025 07:25

Over the holiday season, a coordinated attack was detected and blocked by Microsoft Threat Intelligence security analysts, involving tens of thousands of emails crafted to deceive recipients.

The cybercriminal group known as Storm-0900 launched a large-scale phishing campaign, targeting users across the United States. The campaign exploited two main social engineering themes : fake parking ticket notifications and fraudulent medical test results.

Microsoft Threat Intelligence analysts and security researchers discovered that this campaign led to the spread of XWorm, a widespread modular remote access malware used by many threat actors across the cyber threat landscape.

In connection with the Thanksgiving holiday, attackers created a sense of credibility and urgency that lessened victims’ suspicions and increased the likelihood of users being implicated.

The campaign’s success relied on multiple layers of deception and technical sophistication. The phishing emails contained URLs that directed to an attacker-controlled landing page hosted on the malicious domain permit-service[.]top.

To enhance the deception, the attackers integrated interactive features to bypass security measures and further deceive users. Users were prompted to perform a specific action via a CAPTCHA, by dragging a slider, when accessing the landing page.

This step seemed legitimate to most users, but in reality it served to validate the target’s ability to interact and its susceptibility to malware distribution.

Once the user has successfully interacted with the phishing page, the compromised devices receive the malware, which would allow attackers to establish lasting control and access.

XWorm functions as a modular malware platform, meaning threat actors can load different plugins to perform various tasks on compromised devices.

Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

Cropped RHC 3d Transp2 1766828557 300x300
The editorial staff of Red Hot Cyber is composed of IT and cybersecurity professionals, supported by a network of qualified sources who also operate confidentially. The team works daily to analyze, verify, and publish news, insights, and reports on cybersecurity, technology, and digital threats, with a particular focus on the accuracy of information and the protection of sources. The information published is derived from direct research, field experience, and exclusive contributions from national and international operational contexts.