MEME#4CHAN is a phishing-led malware campaign tracked for delivering the XWorm remote access trojan, including XWorm v3.1, through malicious Microsoft Word documents that exploit CVE-2022-30190 rather than relying on macros. The operation has used hospitality-themed lures such as hotel reservation and booking requests to induce victims to open weaponized documents. Observed targets include businesses in Germany, including manufacturing and healthcare organizations. The intrusion chain uses external relationship objects in Office documents to retrieve staged content and execute PowerShell, followed by heavily obfuscated JScript, C#, and .NET components. The campaign has relied on public file-hosting and blogging services for staging and payload delivery. Execution has included .NET reflection for in-memory loading of malicious assemblies and process injection into legitimate Windows processes, culminating in deployment of XWorm. MEME#4CHAN demonstrates substantial defense-evasion and persistence tradecraft. Observed behaviors include AMSI bypass, weakening of Microsoft Defender protections through exclusions, disabling of the Windows Firewall, scheduled-task persistence, and copying components into the Startup folder. In some cases the activity also created a local administrator account to facilitate continued access. Post-compromise functionality associated with the delivered XWorm payload includes remote command execution, PowerShell execution, file download and execution, screenshot capture, clipboard monitoring, shell access, host reconnaissance, and DDoS capability. The campaign has not been conclusively attributed to a known nation-state or established intrusion set. Similarities to TA558-style hospitality-themed phishing have been noted, but no positive attribution is established on the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
75 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing/attack campaign using in-memory process injection via PowerShell and .NET reflection to load payloads into legitimate processes.
Ongoing phishing-led malware campaign using malicious Word documents exploiting CVE-2022-30190 to launch obfuscated PowerShell, establish persistence, disable defenses, and deliver XWorm v3.1 via reflective/in-memory .NET assembly execution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.