Colombia's national cyber emergency team, colCERT, is warning about a phishing campaign that dresses malware up as an official compliance demand. The lure is a compressed file holding a script called "Requerimiento de acreditación de cumplimiento.js", roughly "request for proof of compliance", and opening it starts a chain that, according to colCERT's analysis, ends with a keylogger and a remote access trojan on the victim's PC.
The agency rates the risk as HIGH in alert AL-122, issued on 2 October 2026 under TLP:CLEAR, and its advice is blunt: any credential or other information typed on an infected machine should be considered exposed.
A paperwork lure built to look routine
The file name is the whole social engineering trick. colCERT says it is designed to impersonate a legitimate administrative or regulatory communication, the kind of request an accounts or legal team expects to answer rather than question. It is a familiar play in Colombia, where recent campaigns have leaned on fake court and judicial notices to deliver AsyncRAT and other remote access malware.
Most of the chain never touches the disk
colCERT traced the execution step by step:
- The JavaScript file runs through wscript.exe, the Windows script host.
- That launches PowerShell with an obfuscated payload hidden in an environment variable named MYWIJ.
- A PowerShell loader runs code directly in memory and deletes itself to hinder analysis.
- The malicious code is injected into choice.exe, a legitimate Windows binary, and a further component is deployed into jsc.exe.
- The jsc.exe component installs keyboard hooks through the SetWindowsHookEx API, turning it into a keylogger.
This is what defenders call living off the land: the attacker borrows signed Windows programs to host the malicious code, so what runs on the machine looks like ordinary system processes. colCERT describes the overall pattern, an archive carrying a script that starts a fileless chain and ends with a RAT talking to dynamic DNS infrastructure, as a recurring one in remote access campaigns.
The trail points to XWorm
For command and control, the malware uses subdomains of DuckDNS, a free dynamic DNS service, and makes outbound connections to external IP addresses over the non-standard ports 3008 and 3010. colCERT says one of those domains shows a high-confidence association with XWorm, a commercially sold remote access trojan. Capabilities documented for XWorm in open sources include keylogging, screen and webcam capture, file management, remote command execution, downloading extra modules and spreading through removable drives.
The agency adds that the loading of media capture modules, together with the nature of the RAT itself, means there is a high probability the attacker has full remote control of the endpoint and can pull down further malicious components.
Block the script host, hunt DuckDNS on odd ports
The behaviour colCERT describes gives defenders several things to look for:
- wscript.exe spawning PowerShell, especially with long or obfuscated content read from environment variables.
- choice.exe or jsc.exe launched from an unexpected parent process or making outbound network connections.
- Outbound traffic to DuckDNS subdomains, particularly on ports 3008 or 3010.
- Script files such as .js or .vbs arriving inside compressed email attachments, which many organizations can simply block at the mail gateway.
Where a machine turns out to be infected, the safe assumption is the one colCERT spells out: every password and token typed on it is gone, and the endpoint belongs to the attacker until it is rebuilt. The lure only works because compliance paperwork is something people are trained to deal with quickly, which is exactly why it keeps being used. More context on the country's threat picture is on our Colombia profile.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.