Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4

https://hackread.com/wp-content/uploads/2026/05/hackers-pyinstaller-amsi-patching-xworm-rat-v7-4-1024x572.jpg

Cybersecurity researchers at Point Wild recently found a new way that cyberattackers are gaining unauthorised access to computers. The investigation, led by experts Kedar Shashikant Pandit, Prathamesh Shingare, and Amol Swami from the Lat61 Threat Intelligence Team, reveals that a common tool used by legitimate developers is being twisted by hackers to hide a nasty malware called XWorm.

Attack Details

The attack starts with a trick email or a fake software update, involving a harmless-looking file. This file is bundled with malicious code using PyInstaller, which is a tool to help programmers turn their scripts into an easy-to-run app. However, in this attack, it is converted into a delivery method for the threat.

When the victim opens the file, it runs a compiled script: BA4Q6ACPMNrd980FwZn9iEbEqkjvRmw7FhW.pyc that works in the background without showing any windows.

Discover more

Affiliate marketing guide

VPN services

Hacker training courses

Point Wild’s investigation further revealed...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more

https://www.eu-startups.com/wp-content/uploads/2026/05/Untitled-design-2026-05-19T165310.544.jpg

Berlin-based bunch, an AI-native platform for managers and institutional investors to manage the entire fund lifecycle, raised a €30.1M Series B led by Portage

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. Protecting your Cloud Applications Data — Backing up Office 365, Google Workspace, Dropbox & Salesforce data